Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45w6-c976-v24q

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.

EPSS

Процентиль: 30%
0.00366
Низкий

8.2 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 8.2
redhat
около 1 месяца назад

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.

CVSS3: 8.2
nvd
около 1 месяца назад

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.

EPSS

Процентиль: 30%
0.00366
Низкий

8.2 High

CVSS3

Дефекты

CWE-290