Описание
A flaw was found in Contour. When an HTTPProxy is configured with both a fallback certificate and JWT (JSON Web Token) providers, Contour does not properly enforce JWT verification. This allows remote attackers to bypass security checks by sending requests without a valid token, specifically when clients do not provide a TLS Server Name Indication (SNI) or provide an unrecognized SNI. The consequence is unauthorized access to upstream services and potential information disclosure.
Отчет
A flaw was found in Contour. When an HTTPProxy combines enableFallbackCertificate with jwtProviders, requests without TLS SNI bypass JWT verification and are proxied without a valid token.
Меры по смягчению последствий
Upgrade to Contour v1.33.5 or later. As a workaround, do not enable enableFallbackCertificate on HTTPProxy resources that also define jwtProviders.
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
6.5 Medium
CVSS3