Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.
| Vendor | Product | Versions |
|---|---|---|
| cilium | cilium | < 1.17.14, >= 1.18.0, < 1.18.8, >= 1.19.0, < 1.19.2 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| go | github.com/cilium/cilium | GHSA | 85% |
Updated affected versions to include < 1.17.13, < 1.18.7, < 1.19.1, changed severity to HIGH, and updated CVSS estimate to 7.0.
Initial creation