Описание
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the EnvoyProxy
API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.
A flaw was found in Envoy Gateway. This vulnerability allows a user with access to a Kubernetes cluster where Envoy Gateway is installed to use a path traversal attack to execute Envoy Admin interface commands on proxies managed by Envoy Gateway. The admin interface can terminate the Envoy process and extract the Envoy configuration, possibly containing confidential data.
Отчет
This vulnerability marked as Important rather than Moderate due to its potential to compromise the core functionality and security of the Envoy Gateway. The path traversal exploit enables attackers within the Kubernetes cluster to access the Envoy Admin interface, which is highly privileged and designed for debugging and operational control. By exploiting this flaw, attackers can terminate critical processes or retrieve sensitive configuration data, such as API keys, secrets, or routing rules, directly impacting the confidentiality, integrity, and availability of the system.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Connectivity Link 1 | rhcl-operator-bundle-container | Affected | ||
Red Hat Connectivity Link 1 | rhcl-operator-container | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.1 High
CVSS3
Связанные уязвимости
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the `EnvoyProxy` API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.
Envoy Admin Interface Exposed through prometheus metrics endpoint
7.1 High
CVSS3