VYPR

apk package

wolfi/hubble-ui-backend

pkg:apk/wolfi/hubble-ui-backend

Vulnerabilities (86)

  • CVE-2023-41333MedSep 27, 2023
    affected < 0fixed 0

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to create or modify CiliumNetworkPolicy objects in a particular namespace is able to affect traffic on an entire Cilium cluster, potentially bypassing policy en

  • CVE-2023-41332LowSep 27, 2023
    affected < 0fixed 0

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In Cilium clusters where Cilium's Layer 7 proxy has been disabled, creating workloads with `policy.cilium.io/proxy-visibility` annotations (in Cilium >= v1.13) or `io.cilium.proxy-visibilit

  • CVE-2023-39347HigSep 27, 2023
    affected < 0fixed 0

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to update pod labels can cause Cilium to apply incorrect network policies. This issue arises due to the fact that on pod update, Cilium incorrectly uses user-pr

  • CVE-2023-34242LowJun 15, 2023
    affected < 0.12.0-r0fixed 0.12.0-r0

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to version 1.13.4, when Gateway API is enabled in Cilium, the absence of a check on the namespace in which a ReferenceGrant is created could result in Cilium unintentionally gaining v

  • CVE-2023-30851LowMay 25, 2023
    affected < 0.12.0-r0fixed 0.12.0-r0

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to multiple `toEndpoints` AND have an allow-all rule in place that affects only one of those endpoints. In such cases, a wi

  • CVE-2023-29002HigApr 18, 2023
    affected < 0.12.0-r0fixed 0.12.0-r0

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of the `cilium-secrets` namespace. This could include data such as TLS private keys for Ingress and GatewayAPI resources. An attacker wi

Page 5 of 5