Risk | High |
Patch available | YES |
Number of vulnerabilities | 6 |
CVE-ID | CVE-2023-27496 CVE-2023-27487 CVE-2023-27491 CVE-2023-27492 CVE-2023-27493 CVE-2023-27488 |
CWE-ID | CWE-20 CWE-770 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
envoy Server applications / IDS/IPS systems, Firewalls and proxy servers |
Vendor | Cloud Native Computing Foundation |
Security Bulletin
This security bulletin contains information about 6 vulnerabilities.
EUVDB-ID: #VU74473
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-27496
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when a redirect url without a state param is received in the oauth filter. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsenvoy: 1.0.0 - 1.25.3
CPE2.3https://github.com/envoyproxy/envoy/security/advisories/GHSA-j79q-2g66-2xv5
https://github.com/envoyproxy/envoy/releases/tag/v1.25.4
https://github.com/envoyproxy/envoy/releases/tag/v1.24.5
https://github.com/envoyproxy/envoy/releases/tag/v1.23.7
https://github.com/envoyproxy/envoy/releases/tag/v1.22.10
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74480
Risk: High
CVSSv4.0: 6.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2023-27487
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the "header x-envoy-original-path". A remote attacker can gain access to sensitive information on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsenvoy: 1.0.0 - 1.25.3
CPE2.3https://github.com/envoyproxy/envoy/security/advisories/GHSA-5375-pq35-hf2g
https://github.com/envoyproxy/envoy/releases/tag/v1.25.4
https://github.com/envoyproxy/envoy/releases/tag/v1.24.5
https://github.com/envoyproxy/envoy/releases/tag/v1.23.7
https://github.com/envoyproxy/envoy/releases/tag/v1.22.10
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74477
Risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-27491
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input within the HTTP/2 and HTTP/3 downstream headers. A remote attacker can bypass the security policies.
MitigationInstall updates from vendor's website.
Vulnerable software versionsenvoy: 1.0.0 - 1.25.3
CPE2.3https://datatracker.ietf.org/doc/html/rfc9114#section-4.3.1
https://github.com/envoyproxy/envoy/security/advisories/GHSA-5jmv-cw9p-f9rp
https://www.rfc-editor.org/rfc/rfc9110#section-5.6.2
https://datatracker.ietf.org/doc/html/rfc9113#section-8.3
https://github.com/envoyproxy/envoy/releases/tag/v1.25.4
https://github.com/envoyproxy/envoy/releases/tag/v1.24.5
https://github.com/envoyproxy/envoy/releases/tag/v1.23.7
https://github.com/envoyproxy/envoy/releases/tag/v1.22.10
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74476
Risk: Medium
CVSSv4.0: 1.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-27492
CWE-ID:
CWE-770 - Allocation of Resources Without Limits or Throttling
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists when a large request body is processed in Lua filter. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsenvoy: 1.0.0 - 1.25.3
CPE2.3https://github.com/envoyproxy/envoy/security/advisories/GHSA-wpc2-2jp6-ppg2
https://github.com/envoyproxy/envoy/releases/tag/v1.25.4
https://github.com/envoyproxy/envoy/releases/tag/v1.24.5
https://github.com/envoyproxy/envoy/releases/tag/v1.23.7
https://github.com/envoyproxy/envoy/releases/tag/v1.22.10
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74475
Risk: High
CVSSv4.0: 6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2023-27493
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not sanitize or escape request properties when generating request headers. A remote attacker can cause request smuggling and bypass of security policies.
MitigationInstall updates from vendor's website.
Vulnerable software versionsenvoy: 1.0.0 - 1.25.3
CPE2.3https://github.com/envoyproxy/envoy/security/advisories/GHSA-w5w5-487h-qv8q
https://github.com/envoyproxy/envoy/releases/tag/v1.25.4
https://github.com/envoyproxy/envoy/releases/tag/v1.24.5
https://github.com/envoyproxy/envoy/releases/tag/v1.23.7
https://github.com/envoyproxy/envoy/releases/tag/v1.22.10
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74474
Risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-27488
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input when "failure_mode_allow: true" is configured for ext_authz filter. A remote attacker can pass specially crafted input to the application and gain elevated privileges on the target system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsenvoy: 1.0.0 - 1.25.3
CPE2.3https://github.com/envoyproxy/envoy/security/advisories/GHSA-9g5w-hqr3-w2ph
https://github.com/envoyproxy/envoy/releases/tag/v1.25.4
https://github.com/envoyproxy/envoy/releases/tag/v1.24.5
https://github.com/envoyproxy/envoy/releases/tag/v1.23.7
https://github.com/envoyproxy/envoy/releases/tag/v1.22.10
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.