Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0752

Опубликовано: 21 янв. 2025
Источник: redhat
CVSS3: 7.1

Описание

A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.

Отчет

This IMPORTANT flaw in OpenShift Service Mesh 2.6.3 and 2.5.6 allows an attacker to bypass HTTP header sanitization in Envoy. This can lead to rate-limiter avoidance, access-control bypass, and resource exhaustion, potentially resulting in denial-of-service or unauthorized access within the service mesh environment. The vulnerability impacts deployments utilizing these specific versions of OpenShift Service Mesh.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2339115envoyproxy: OpenShift Service Mesh Envoy HTTP Header Sanitization Bypass Leading to DoS and Unauthorized Access

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
больше 1 года назад

A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.

CVSS3: 6.3
github
больше 1 года назад

A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.

7.1 High

CVSS3