Affected by GO-2022-0959
and 9 other vulnerabilities
GO-2022-0959 : Network Policies & (Clusterwide) Cilium Network Policies with namespace label selectors may unexpectedly select pods with maliciously crafted labels in github.com/cilium/cilium
GO-2023-1643 : Potential network policy bypass when routing IPv6 traffic in github.com/cilium/cilium
GO-2023-1730 : Debug mode leaks confidential data in Cilium in github.com/cilium/cilium
GO-2023-1785 : Potential HTTP policy bypass when using header rules in Cilium in github.com/cilium/cilium
GO-2023-2078 : Kubernetes users may update Pod labels to bypass network policy in github.com/cilium/cilium
GO-2023-2079 : Specific Cilium configurations vulnerable to DoS via Kubernetes annotations in github.com/cilium/cilium
GO-2023-2080 : Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy in github.com/cilium/cilium
GO-2024-2656 : Unencrypted traffic between nodes with IPsec in github.com/cilium/cilium
GO-2024-2666 : Insecure IPsec transparent encryption in github.com/cilium/cilium
GO-2024-3072 : Policy bypass for Host Firewall policy due to race condition in Cilium agent in github.com/cilium/cilium
Discover Packages
github.com/cilium/cilium
pkg
bgp
fence
package
Version:
v1.11.7
Opens a new window with list of versions in this module.
Published: Jul 15, 2022
License: Apache-2.0
Opens a new window with license information.
Imports: 4
Opens a new window with list of imports.
Imported by: 1
Opens a new window with list of known importers.
Documentation
Documentation
¶
Fencer provides a method set to prevent processing out of order events.
Fencer will keep track of the last seen revision (monotonically increasing event id)
for each seen UUID (globally unique identifier for a resource producing an event.)
Clear removes the uuid and revision from its
internal storage.
This method should only be invoked once the caller
can ensure the provided UUID will not be seen again.
Fence evalutes the passed in meta and informs the caller
whether to not process the event (fence) or not process
the event (no fence)
True is returned when the caller should fence the event.
False is returned when the caller should not.
Meta provides metadata from the resource which
triggered this package's events.
FromSlimObjectMeta allocates a meta derived from
a k8s ObjectMeta and stores it at the memory
pointed to by m.
FromSlimObjectMeta allocates a meta derived from
a slim k8s ObjectMeta and stores it at the memory
pointed to by m.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.