CVE-2024-42487

MEDIUM EPSS 41.1%
Published Aug 15, 20241y ago · Modified Jun 17, 20261w ago
4.3 CVSS 3.1
Medium
Find Similar
Published Aug 15, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in the Gateway API specification. In particular, request headers are matched before request methods, when the specification describes that the request methods must be respected before headers are matched. This could result in unexpected behaviour with security This issue is fixed in Cilium v1.15.8 and v1.16.1. There is no workaround for this issue.

CVSS Details

Base Score
4.3
Exploitability
2.8
Impact
1.4
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity None
Availability None

Threat Intelligence

EPSS Exploit Probability
41.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 2

CWE-113
CWE-436

Affected Products 2

VendorProductVersionRange
ciliumcilium*≥1.15.0  –  <1.15.8
ciliumcilium1.16.0any

References 3

  • github.com https://github.com/cilium/cilium/commit/a3510fe4a92305822aa1a5e08cb6d6c873c8699a
    PatchThird Party Advisory
  • github.com https://github.com/cilium/cilium/pull/34109
    PatchThird Party Advisory
  • github.com https://github.com/cilium/cilium/security/advisories/GHSA-qcm3-7879-xcww
    Vendor Advisory

Remediation

  • github.com https://github.com/cilium/cilium/commit/a3510fe4a92305822aa1a5e08cb6d6c873c8699a
    PatchThird Party Advisory
  • github.com https://github.com/cilium/cilium/pull/34109
    PatchThird Party Advisory