Bug ID 1209644
Summary VUL-0: CVE-2023-28114: cilium-cli: user permissions on etcd are overwritten when configuring a cluster mesh
Classification openSUSE
Product openSUSE Tumbleweed
Version Current
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee opensuse_buildservice@ojkastl.de
Reporter carlos.lopez@suse.com
QA Contact security-team@suse.de
Found By ---
Blocker ---

CVE-2023-28114

`cilium-cli` is the command line interface to install, manage, and troubleshoot
Kubernetes clusters running Cilium. Prior to version 0.13.2,`cilium-cli`, when
used to configure cluster mesh functionality, can remove the enforcement of
user
permissions on the `etcd` store used to mirror local cluster information to
remote clusters. Users who have set up cluster meshes using the Cilium Helm
chart are not affected by this issue. Due to an incorrect mount point
specification, the settings specified by the `initContainer` that configures
`etcd` users and their permissions are overwritten when using `cilium-cli` to
configure a cluster mesh. An attacker who has already gained access to a valid
key and certificate for an `etcd` cluster compromised in this manner could then
modify state in that `etcd` cluster. This issue is patched in `cilium-cli`
0.13.2. As a workaround, one may use Cilium's Helm charts to create their
cluster.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-28114
https://www.cve.org/CVERecord?id=CVE-2023-28114
https://artifacthub.io/packages/helm/cilium/cilium
https://github.com/cilium/cilium-cli/commit/fb1427025764e1eebc4a7710d902c4f22cae2610
https://github.com/cilium/cilium-cli/releases/tag/v0.13.2
https://github.com/cilium/cilium-cli/security/advisories/GHSA-6f27-3p6c-p5jc


You are receiving this mail because: