CVE-2024-28250
MEDIUMDescription
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies Wireguard-eligible traffic that is sent between a node's Envoy proxy and pods on other nodes is sent unencrypted and Wireguard-eligible traffic that is sent between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue has been resolved in Cilium 1.14.8 and 1.15.2 in in native routing mode (`routingMode=native`) and in Cilium 1.14.4 in tunneling mode (`routingMode=tunnel`). Not that in tunneling mode, `encryption.wireguard.encapsulate` must be set to `true`. There is no known workaround for this issue.
Is your site exposed to CVE-2024-28250?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cilium | cilium |
| cilium | cilium |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-28250? +
How severe is CVE-2024-28250? +
What products are affected by CVE-2024-28250? +
How do I check if I'm vulnerable to CVE-2024-28250? +
Related Vulnerabilities
Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT …
Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2.
Sensitive customer information is stored in the device without encryption.
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to the …
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to …
The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy …