Vulnerability Report: GO-2024-2653
- CVE-2024-28248, GHSA-68mj-9pjq-mc85
- Affects: github.com/cilium/cilium
- Published: Mar 22, 2024
- Modified: May 20, 2024
Cilium's HTTP policies are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped.
Affected Modules
-
PathGo Versions
-
from v1.13.9 before v1.13.13, from v1.14.0 before v1.14.8, from v1.15.0 before v1.15.2
Aliases
References
- https://docs.cilium.io/en/stable/security/policy/language/#http
- https://vuln.go.dev/ID/GO-2024-2653.json
Credits
- @romikps, @sayboras, @jrajahalme
Feedback
See anything missing or incorrect?
Suggest an edit to this report.