Affected by GO-2024-3072
and 5 other vulnerabilities
GO-2024-3072 : Policy bypass for Host Firewall policy due to race condition in Cilium agent in github.com/cilium/cilium
GO-2024-3208 : Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present in github.com/cilium/cilium
GO-2025-3415 : DoS in Cilium agent DNS proxy from crafted DNS responses in github.com/cilium/cilium
GO-2025-3416 : Cilium has an information leakage via insecure default Hubble UI CORS header in github.com/cilium/cilium
GO-2025-3635 : In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters in github.com/cilium/cilium
GO-2025-4167 : Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic in Ciliumgithub.com/cilium/cilium
Discover Packages
github.com/cilium/cilium
operator
auth
package
Version:
v1.14.13
Opens a new window with list of versions in this module.
Published: Jul 11, 2024
License: Apache-2.0
Opens a new window with license information.
Imports: 9
Opens a new window with list of imports.
Imported by: 2
Opens a new window with list of known importers.
Documentation
Documentation
¶
Package auth provides routines to manage mutual authentication identities in Cilium.
If enabled, the operator will watch for CiliumIdentity resources and provision
corresponding external identities such as SPIFFE identities.
type Config struct {
Enabled bool `mapstructure:"mesh-auth-mutual-enabled"`
}
Config contains the configuration for the identity-gc.
Flags implements cell.Flagger interface.
type IdentityWatcher struct {
}
IdentityWatcher represents the Cilium identities watcher.
It watches for Cilium identities and upserts or deletes them in Spire.
Source Files
¶
Directories
¶
Click to show internal directories.
Click to hide internal directories.