Sensitive Data Exposure in Cilium's Hubble UI Component
CVE-2025-23047

6.5MEDIUM

Key Information:

Vendor

Cilium

Status
Vendor
CVE Published:
22 January 2025

What is CVE-2025-23047?

An insecure default 'Access-Control-Allow-Origin' header in Cilium's Hubble UI can lead to exposure of sensitive configuration details about Kubernetes clusters. Users running Cilium versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, or 1.16.0 through 1.16.4 may be at risk. An attacker could exploit this vulnerability by tricking a victim into visiting a malicious page, allowing access to node names, IP addresses, and other critical cluster metadata. The issue is resolved in Cilium versions 1.14.18, 1.15.12, and 1.16.5, and users can implement a workaround by modifying the CORS headers in the Helm template.

Affected Version(s)

cilium >= 1.14.0, < 1.14.18 < 1.14.0, 1.14.18

cilium >= 1.15.0, < 1.15.12 < 1.15.0, 1.15.12

cilium >= 1.16.0, < 1.16.5 < 1.16.0, 1.16.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.