Database/Container, Kubernetes & orchestration
Envoy: Client can forge the x-envoy-original-path header and bypass JWT checks
CVSS 8.2CVE-2023-27487Container, Kubernetes & orchestrationcurated
Impact
Client can forge the x-envoy-original-path header and bypass JWT checks
Who can reach it
Unauthenticated network
What to do
Upgrade Envoy; strip x-envoy headers at the edge
References
Related entries
- Envoy: Mixed-case HTTP/2 schemes defeat case-sensitive internal scheme checksCVE-2023-35944 · EnvoyHigh
- Envoy: Escaped slash sequences %2F and %5C not decodedCVE-2021-29492 · EnvoyHigh
- Envoy: Request properties are not escaped when generating request headersCVE-2023-27493 · EnvoyHigh
- Envoy: Decompressor accumulates unbounded dataCVE-2022-29225 · EnvoyHigh
- Envoy: "HTTP/2 Rapid Reset": stream-cancellation flood exhausts server resourcesCVE-2023-44487 · EnvoyHigh
- Envoy: Stream-management bugs in the default oghttp HTTP/2 codecCVE-2024-45807 · EnvoyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.