Input validation error in envoy - CVE-2023-35944

 

Input validation error in envoy - CVE-2023-35944

Published: July 26, 2023


Vulnerability identifier: #VU78679
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35944
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to incorrect handling of requests and responses with mixed case schemes. A remote attacker can pass specially crafted input to the application and bypass some requests with mixed schemes.


Affected software

envoy
Amazon Linux AMI
Istio
OpenShift Service Mesh

How to mitigate CVE-2023-35944

Install updates from vendor's website.

envoy - addressed in versions 1.23.12, 1.24.10, 1.25.9, 1.26.4
Istio - addressed in versions 1.16.7, 1.17.5, 1.18.2
OpenShift Service Mesh - addressed in versions 2.2.10, 2.3.6, 2.4.2

External References

Related Security Bulletins