Sensitive Data Exposure in Cilium's Hubble UI Component
CVE-2025-23047
What is CVE-2025-23047?
An insecure default 'Access-Control-Allow-Origin' header in Cilium's Hubble UI can lead to exposure of sensitive configuration details about Kubernetes clusters. Users running Cilium versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, or 1.16.0 through 1.16.4 may be at risk. An attacker could exploit this vulnerability by tricking a victim into visiting a malicious page, allowing access to node names, IP addresses, and other critical cluster metadata. The issue is resolved in Cilium versions 1.14.18, 1.15.12, and 1.16.5, and users can implement a workaround by modifying the CORS headers in the Helm template.
Affected Version(s)
cilium >= 1.14.0, < 1.14.18 < 1.14.0, 1.14.18
cilium >= 1.15.0, < 1.15.12 < 1.15.0, 1.15.12
cilium >= 1.16.0, < 1.16.5 < 1.16.0, 1.16.5