Skip to content

x/vulndb: potential Go vuln in github.com/cilium/cilium: GHSA-j89h-qrvr-xc36 #2656

Closed
@GoVulnBot

Description

@GoVulnBot

In GitHub Security Advisory GHSA-j89h-qrvr-xc36, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/cilium/cilium 1.15.2 >= 1.15.0, < 1.15.2

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/cilium/cilium
      versions:
        - introduced: 1.15.0
          fixed: 1.15.2
      vulnerable_at: 1.15.1
      packages:
        - package: github.com/cilium/cilium
    - module: github.com/cilium/cilium
      versions:
        - introduced: 1.14.0
          fixed: 1.14.8
      vulnerable_at: 1.14.7
      packages:
        - package: github.com/cilium/cilium
    - module: github.com/cilium/cilium
      versions:
        - fixed: 1.13.13
      vulnerable_at: 1.13.12
      packages:
        - package: github.com/cilium/cilium
summary: Unencrypted traffic between nodes when using IPsec and L7 policies
cves:
    - CVE-2024-28249
ghsas:
    - GHSA-j89h-qrvr-xc36
references:
    - advisory: https://github.com/cilium/cilium/security/advisories/GHSA-j89h-qrvr-xc36
    - advisory: https://github.com/advisories/GHSA-j89h-qrvr-xc36

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions