Cilium Fixes Issue with HTTP Policies Not Consistently Applied
CVE-2024-28248
What is CVE-2024-28248?
Cilium, a networking, observability, and security solution developed by Isovalent, encountered an issue where HTTP policies were not properly enforced across all traffic. This inconsistency resulted in certain HTTP traffic being incorrectly forwarded instead of being dropped, posing potential security risks. This vulnerability affects versions of Cilium before the updates introduced in 1.13.13, 1.14.8, and 1.15.2. No workarounds are available, making it essential for users to update to the patched versions to ensure robust security and compliance with HTTP policies.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cilium >= 1.13.9, < 1.13.13 < 1.13.9, 1.13.13
cilium >= 1.14.0, < 1.14.8 < 1.14.0, 1.14.8
cilium >= 1.15.0, < 1.15.2 < 1.15.0, 1.15.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
