Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue has been resolved in Cilium 1.15.2, 1.14.8, and 1.13.13. There is no known workaround for this issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-03-18T21:36:10.510Z

Updated: 2024-08-02T00:48:49.660Z

Reserved: 2024-03-07T14:33:30.036Z

Link: CVE-2024-28249

cve-icon Vulnrichment

Updated: 2024-05-23T19:01:18.629Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-18T22:15:08.503

Modified: 2024-11-21T09:06:05.707

Link: CVE-2024-28249

cve-icon Redhat

No data.