Improper Authorization in envoy - CVE-2021-32777

 

Improper Authorization in envoy - CVE-2021-32777

Published: August 26, 2021


Vulnerability identifier: #VU56106
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32777
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization process.

The vulnerability exists due to an error in ext-authz extension when sending request headers to the external authorization service in Envoy. The application sends only the last header instead of merging multiple value headers according to the HTTP specification. A remote attacker can bypass authorization process and gain unauthorized access to the application, if ext-authz extension is used.


Affected software

envoy
Istio
servicemesh-proxy (Red Hat package)
servicemesh (Red Hat package)

How to mitigate CVE-2021-32777

Install updates from vendor's website.

envoy - addressed in versions 1.16.5, 1.17.4, 1.18.4, 1.19.1
Istio - addressed in versions 1.9.8, 1.10.4, 1.11.1
servicemesh-proxy (Red Hat package) - addressed in versions 1.1.17-2.el8, 2.0.7-3.el8
servicemesh (Red Hat package) - addressed in versions 1.1.17-3.el8, 2.0.7-3.el8

External References

Related Security Bulletins