CVE-2024-28248
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Mar 18, 2024
Updated: Jan 9, 2025
CWE ID 693
Summary
CVE-2024-28248 is a vulnerability affecting Cilium, a networking, observability, and security solution. Versions 1.13.9 and prior to 1.13.13, 1.14.8, and 1.15.2 have an issue where HTTP policies are not consistently applied, resulting in intermittent forwarding of HTTP traffic that should have been dropped. This security flaw could potentially expose organizations to unintended network traffic. Patches for this issue have been released in versions 1.15.2, 1.14.8, and 1.13.13. Sadly, there are no known workarounds for affected versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Cilium