Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, a malicious client is able to construct credentials with permanent validity in some specific scenarios. This is caused by the some rare scenarios in which HMAC payload can be always valid in OAuth2 filter's check. Versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12 have a fix for this issue. As a workaround, avoid wildcards/prefix domain wildcards in the host's domain configuration.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ecs-service-connect-agent | Sep 7, 2023 | Jul 25, 2023 |
| Amazon_linux_2023 | — | Upgrade ecs-service-connect-agent | Feb 17, 2025 | Jul 25, 2023 |
| Oracle_linux | — | Upgrade olcne-multus-chartUpgrade olcne-olm-chartUpgrade virtctlUpgrade olcne-agentUpgrade olcne-api-serverUpgrade olcne-oci-ccm-chartUpgrade olcne-gluster-chartUpgrade olcne-metallb-chartUpgrade olcne-utilsUpgrade olcne-kubevirt-chartUpgrade istioUpgrade olcne-rook-chartUpgrade olcne-prometheus-chartUpgrade istio-istioctlUpgrade olcne-grafana-chartUpgrade olcne-calico-chartUpgrade olcne-istio-chartUpgrade olcne-nginxUpgrade olcnectl | Sep 6, 2023 | Jul 25, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub