Improper access control in Fastify-http-proxy - CVE-2021-21322
Published: February 23, 2021 / Updated: July 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to access unintended proxied backend resources and disclose or modify sensitive information.
The vulnerability exists due to improper access control in the URL prefix handling of fastify-http-proxy when processing a specially crafted URL. A remote attacker can send a specially crafted request to access unintended proxied backend resources and disclose or modify sensitive information.
Affected software
Red Hat Advanced Cluster Management for Kubernetes
How to mitigate CVE-2021-21322
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.2