CyberRota Analysis
AI-GeneratedEnvoy's ext_authz filter is vulnerable to a denial-of-service attack due to improper handling of path-less CONNECT requests, which can lead to a crash of the Envoy process when query-parameter mutations are applied. This issue affects deployments that accept path-less CONNECT requests and utilize the ext_authz filter for authorization. Organizations using affected versions should prioritize upgrading to versions 1.36.10, 1.37.6, 1.38.4, or 1.39.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onComplete dereferences that pointer while parsing the query string. An unauthenticated downstream client can crash the Envoy process when the filter and authorization response use query-parameter mutation. The relevant scope boundary is that the deployment must accept path-less CONNECT and configure ext_authz query-parameter mutation. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)