Логотип exploitDog
bind:CVE-2025-24030
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-24030

Количество 4

Количество 4

redhat логотип

CVE-2025-24030

8 месяцев назад

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the `EnvoyProxy` API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2025-24030

8 месяцев назад

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the `EnvoyProxy` API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-j777-63hf-hx76

8 месяцев назад

Envoy Admin Interface Exposed through prometheus metrics endpoint

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0297-1

8 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-24030

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the `EnvoyProxy` API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-24030

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the `EnvoyProxy` API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-j777-63hf-hx76

Envoy Admin Interface Exposed through prometheus metrics endpoint

CVSS3: 7.1
0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0297-1

Security update for govulncheck-vulndb

8 месяцев назад

Уязвимостей на страницу