Unencrypted traffic between pods when using Wireguard and an external kvstore
Vulnerability Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encrypted. This issue affects Cilium v1.14 before v1.14.7 and has been patched in Cilium v1.14.7. There is no workaround to this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25631
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/cilium/cilium/security/advisories/GHSA-x989-52fc-4vr4
- https://docs.cilium.io/en/stable/installation/k8s-install-external-etcd/#when-do-i-need-to-use-a-kvstore
- https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg
- https://github.com/cilium/cilium/releases/tag/v1.14.7
More from cilium
View All →Affected Vendor
cilium
View all reports →