Input validation error in envoy - CVE-2023-27493
Published: April 5, 2023 / Updated: April 6, 2023
Vulnerability identifier: #VU74475
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27493
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not sanitize or escape request properties when generating request headers. A remote attacker can cause request smuggling and bypass of security policies.
Affected software
envoy
Amazon Linux AMI
Istio
OpenShift Service Mesh
Amazon Linux AMI
Istio
OpenShift Service Mesh
How to mitigate CVE-2023-27493
Install updates from vendor's website.
envoy - addressed in versions 1.22.10, 1.23.7, 1.24.5, 1.25.4
Istio - addressed in versions 1.15.7, 1.16.4, 1.17.2
OpenShift Service Mesh - update to 2.2.9
Istio - addressed in versions 1.15.7, 1.16.4, 1.17.2
OpenShift Service Mesh - update to 2.2.9
External References
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-w5w5-487h-qv8q
- https://github.com/envoyproxy/envoy/releases/tag/v1.25.4
- https://github.com/envoyproxy/envoy/releases/tag/v1.24.5
- https://github.com/envoyproxy/envoy/releases/tag/v1.23.7
- https://github.com/envoyproxy/envoy/releases/tag/v1.22.10