Database/Container, Kubernetes & orchestration
Cilium: Insecure default Access-Control-Allow-Origin in Hubble UI exposes sensitive observability data
CVSS 6.5CVE-2025-23047Container, Kubernetes & orchestrationcurated
Impact
Insecure default Access-Control-Allow-Origin in Hubble UI exposes sensitive observability data
Who can reach it
Anyone who can get an operator's browser to a hostile page
What to do
Upgrade Cilium; put Hubble UI behind auth
References
Related entries
- Cilium: WireGuard transparent encryption not applied to some pod trafficCVE-2024-25630 · CiliumMedium
- Cilium: With an external kvstore and WireGuard, pod-to-pod traffic is unencryptedCVE-2024-25631 · CiliumMedium
- Cilium: IPsec-eligible traffic matching L7 policy is sent unencryptedCVE-2024-28249 · CiliumMedium
- Cilium: WireGuard-eligible traffic matching L7 policy is sent unencrypted between nodesCVE-2024-28250 · CiliumMedium
- Cilium: With native routing plus WireGuard node encryption, traffic from pods on other nodes is wrongly permittedCVE-2026-26963 · CiliumMedium
- Cilium: A namespaced HTTPRoute can mirror another tenant's HTTP trafficCVE-2026-56742 · CiliumMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.