When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive information or allow disruptive administrative operations, such as:
Exposing TLS secrets
Disrupting traffic in the cluster
Terminating the Envoy process
This issue affects both the embedded and standalone Envoy deployment models.
Patches
This issue affects:
Cilium v1.19 between v1.19.0 and v1.19.1 inclusive
Cilium v1.18 between v1.18.0 and v1.18.7 inclusive
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to moemen for reporting the issue and 0xch4z for their work on triaging and remediating this issue.
If anyone thinks they have found a vulnerability affecting Cilium, it is strongly encouraged to report it to the security mailing list at [email protected]. This is a private mailing list for the Cilium security team, and the report will be treated as a top priority.