CyberRota Analysis
AI-GeneratedCilium versions prior to 1.17.16, as well as 1.18.2 to 1.18.9 and 1.19.0 to 1.19.3, are vulnerable to a flaw that allows users to create CiliumLocalRedirectPolicies with arbitrary ClusterIPs, potentially hijacking traffic to Services across namespaces and undermining security controls. Additionally, deleting such policies may corrupt the internal service state, disrupting service translation. Organizations utilizing Cilium in their networking infrastructure should prioritize upgrading to the patched versions to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.