Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the OAuth filter assumes that a `state` query param is present on any response that looks like an OAuth redirect response. Sending it a request with the URI path equivalent to the redirect path, without the `state` parameter, will lead to abnormal termination of Envoy process. Versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9 contain a patch. The issue can also be mitigated by locking down OAuth traffic, disabling the filter, or by filtering traffic before it reaches the OAuth filter (e.g. via a lua script).
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ecs-service-connect-agent-debuginfoUpgrade ecs-service-connect-agent | Jul 14, 2023 | Apr 4, 2023 |
| Amazon_linux_2023 | — | Upgrade ecs-service-connect-agent | Feb 17, 2025 | Apr 4, 2023 |
| Oracle_linux | — | Upgrade olcne-grafana-chartUpgrade kubeadmUpgrade olcne-gluster-chartUpgrade olcne-oci-ccm-chartUpgrade olcne-olm-chartUpgrade olcne-nginxUpgrade istio-istioctlUpgrade olcne-kubevirt-chartUpgrade olcne-calico-chartUpgrade istioUpgrade olcne-utilsUpgrade kubectlUpgrade olcnectlUpgrade olcne-metallb-chartUpgrade olcne-api-serverUpgrade olcne-agentUpgrade olcne-rook-chartUpgrade olcne-multus-chartUpgrade olcne-extra-modulesUpgrade olcne-istio-chartUpgrade olcne-prometheus-chartUpgrade kubelet | Jun 2, 2023 | Apr 4, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub