Логотип exploitDog
bind:CVE-2022-29226
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-29226

Количество 7

Количество 7

redhat логотип

CVE-2022-29226

больше 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2022-29226

больше 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2022-29226

больше 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

CVSS3: 10
EPSS: Низкий
oracle-oval логотип

ELSA-2022-9589

больше 3 лет назад

ELSA-2022-9589: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9588

больше 3 лет назад

ELSA-2022-9588: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9587

больше 3 лет назад

ELSA-2022-9587: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9586

больше 3 лет назад

ELSA-2022-9586: olcne security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-29226

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

CVSS3: 10
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-29226

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

CVSS3: 10
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-29226

Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

CVSS3: 10
0%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2022-9589

ELSA-2022-9589: olcne security update (IMPORTANT)

больше 3 лет назад
oracle-oval логотип
ELSA-2022-9588

ELSA-2022-9588: olcne security update (IMPORTANT)

больше 3 лет назад
oracle-oval логотип
ELSA-2022-9587

ELSA-2022-9587: olcne security update (IMPORTANT)

больше 3 лет назад
oracle-oval логотип
ELSA-2022-9586

ELSA-2022-9586: olcne security update (IMPORTANT)

больше 3 лет назад

Уязвимостей на страницу