Логотип exploitDog
bind:"CVE-2022-29226"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-29226"

Количество 7

Количество 7

redhat логотип

CVE-2022-29226

около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2022-29226

около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2022-29226

около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

CVSS3: 10
EPSS: Низкий
oracle-oval логотип

ELSA-2022-9589

около 3 лет назад

ELSA-2022-9589: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9588

около 3 лет назад

ELSA-2022-9588: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9587

около 3 лет назад

ELSA-2022-9587: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9586

около 3 лет назад

ELSA-2022-9586: olcne security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-29226

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

CVSS3: 10
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-29226

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

CVSS3: 10
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-29226

Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

CVSS3: 10
0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2022-9589

ELSA-2022-9589: olcne security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-9588

ELSA-2022-9588: olcne security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-9587

ELSA-2022-9587: olcne security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-9586

ELSA-2022-9586: olcne security update (IMPORTANT)

около 3 лет назад

Уязвимостей на страницу