CVE-2023-28114 is a medium-severity vulnerability affecting cilium-cli versions prior to 0.13.2. It allows for the removal of user permission enforcement on the etcd store when cilium-cli is used to configure cluster mesh functionality, potentially allowing an attacker with existing etcd credentials to modify cluster state. The vulnerability has a CVSS score of 4.1 (MEDIUM) with an attack vector of adjacent network and low attack complexity, resulting in a potential impact of low integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.13.2CPE matchmatch criteria | cpe:2.3:a:cilium:cilium-cli:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.