CVE-2024-28250: Unencrypted traffic between nodes when using WireGuard and L7 policies
In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies:
- Traffic that should be WireGuard-encrypted is sent unencrypted between a node’s Envoy proxy and pods on other nodes.
- Traffic that should be WireGuard-encrypted is sent unencrypted between a node’s DNS proxy and pods on other nodes.
References
Detect and mitigate CVE-2024-28250 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →