CVE-2024-42486 impacts Cilium versions 1.15.x prior to 1.15.8 and 1.16.x prior to 1.16.1. This vulnerability stems from improper propagation of ReferenceGrant changes within Cilium's GatewayAPI controller, potentially allowing Gateway resources to retain unauthorized access to secrets or Routes to forward traffic to backends in other namespaces for extended periods. The vulnerability is rated HIGH with a CVSS score of 7.2, indicating a network-exploitable issue with low attack complexity that could lead to limited confidentiality and integrity impacts. The EPSS score is low, suggesting a minimal probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.15.0, <= 1.15.8CPE matchmatch criteria | cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:* | ||
1.16.0CPE matchmatch criteria | cpe:2.3:a:cilium:cilium:1.16.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.