Interpretation Conflict Affecting cilium-cli package, versions <0.16.15-r2
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-WOLFILATEST-CILIUMCLI-7693481
- published 16 Aug 2024
- disclosed 15 Aug 2024
Introduced: 15 Aug 2024
CVE-2024-42487 Open this link in a new tabHow to fix?
Upgrade Wolfi
cilium-cli
to version 0.16.15-r2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream cilium-cli
package and not the cilium-cli
package as distributed by Wolfi
.
See How to fix?
for Wolfi
relevant fixed versions and status.
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in the Gateway API specification. In particular, request headers are matched before request methods, when the specification describes that the request methods must be respected before headers are matched. This could result in unexpected behaviour with security This issue is fixed in Cilium v1.15.8 and v1.16.1. There is no workaround for this issue.