Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9901

Опубликовано: 05 апр. 2019
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy.

A flaw was found in Envoy version 1.9.0 and older, where Envoy does not normalize HTTP URL paths. This flaw allows a remote attacker to craft a path with a relative path and to bypass access control. This issue results in a backend server with the ability to interpret the unnormalized path.

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1698025istio/envoy: Path traversal via URL Patch manipulation in HTTP/1.x header

EPSS

Процентиль: 27%
0.00095
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 7 лет назад

Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy.

CVSS3: 10
github
больше 3 лет назад

EnvoyProxy Envoy Missing HTTP URL path normalization

CVSS3: 10
fstec
почти 7 лет назад

Уязвимость сетевого программного средства Envoy, связанная с ошибками при нормализации URI-адресов, позволяющая нарушителю получить несанкционированный доступ к защищаемым данным

EPSS

Процентиль: 27%
0.00095
Низкий

8.3 High

CVSS3