/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-25630

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-25630

Severity

6.1

Medium

CVSS V3

Summary

Cilium has unencrypted ingress/health traffic when using Wireguard transparent encryption

Description

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, traffic to/from the Ingress and health endpoints is not encrypted. This issue affects Cilium v1.14 before v1.14.7 and has been patched in Cilium v1.14.7. There is no workaround to this issue.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing