cve/2024/CVE-2024-28249.md
2024-05-25 21:48:12 +02:00

19 lines
1.1 KiB
Markdown

### [CVE-2024-28249](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28249)
![](https://img.shields.io/static/v1?label=Product&message=cilium&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C%201.13.13%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-311%3A%20Missing%20Encryption%20of%20Sensitive%20Data&color=brighgreen)
### Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue has been resolved in Cilium 1.15.2, 1.14.8, and 1.13.13. There is no known workaround for this issue.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/NaInSec/CVE-LIST
- https://github.com/fkie-cad/nvd-json-data-feeds