CVE-2023-41332:
Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
3.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.13459%
CWE
Published
9/27/2023
Updated
11/9/2023
KEV Status
No
Technology
Go
Technical Details
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
---|---|---|---|
github.com/cilium/cilium | go | >= 1.14.0, < 1.14.2 | 1.14.2 |
github.com/cilium/cilium | go | < 1.12.14 | 1.12.14 |
github.com/cilium/cilium | go | >= 1.13.0, < 1.13.7 | 1.13.7 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The stack trace shows CreateOrUpdateRedirect being called on a nil proxy instance when L7 is disabled. The fix in PR #27597 adds proxy availability checks in addVisibilityRedirects
and modifies proxy component handling. These functions lacked proper nil checks when processing visibility annotations while the proxy was disabled, leading to segmentation faults.