CVE-2023-30851: Potential HTTP policy bypass when using header rules in Cilium
Impact
This issue only impacts users who:
- Have a HTTP policy that applies to multiple
toEndpoints
AND - Have an allow-all rule in place that affects only one of those endpoints
In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies.
References
Detect and mitigate CVE-2023-30851 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →