SCA: security update for github.com/cilium/cilium (GHSA-r5x6-w42p-jhpp)

critical Tenable Self-Hosted Container Security Plugin ID 418515

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In version
1.13.0, when Cilium is started, there is a short period when Cilium eBPF programs are not attached to the
host. During this period, the host does not implement any of Cilium's featureset. This can cause
disruption to newly established connections during this period due to the lack of Load Balancing, or can
cause Network Policy bypass due to the lack of Network Policy enforcement during the window. This
vulnerability impacts any Cilium-managed endpoints on the node (such as Kubernetes Pods), as well as the
host network namespace (including Host Firewall). This vulnerability is fixed in Cilium 1.13.1 or later.
Cilium releases 1.12.x, 1.11.x, and earlier are not affected. There are no known workarounds.
(CVE-2023-27595)

See Also

https://github.com/advisories/GHSA-r5x6-w42p-jhpp

Plugin Details

Severity: Critical

ID: 418515

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-27595

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/17/2023

Vulnerability Publication Date: 3/17/2023

Reference Information

CVE: CVE-2023-27595

cwe: CWE-755