← Back to CVEs
CVE-2019-9900
HIGH8.3
Description
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
CVE Details
CVSS v3.1 Score8.3
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published4/25/2019
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
envoyproxy:envoyredhat:openshift_service_mesh
Weaknesses (CWE)
CWE-74
References
https://access.redhat.com/errata/RHSA-2019:0741(cve@mitre.org)
https://github.com/envoyproxy/envoy/issues/6434(cve@mitre.org)
https://access.redhat.com/errata/RHSA-2019:0741(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/envoyproxy/envoy/issues/6434(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/envoyproxy/envoy/security/advisories/GHSA-x74r-f4mw-c32h(af854a3a-2127-422b-91ae-364da2661108)
https://groups.google.com/forum/#%21topic/envoy-announce/VoHfnDqZiAM(af854a3a-2127-422b-91ae-364da2661108)
https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_history(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.