Input validation error in envoy - CVE-2023-35944
Published: July 26, 2023
Vulnerability identifier: #VU78679
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35944
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to incorrect handling of requests and responses with mixed case schemes. A remote attacker can pass specially crafted input to the application and bypass some requests with mixed schemes.
Affected software
envoy
Amazon Linux AMI
Istio
OpenShift Service Mesh
Amazon Linux AMI
Istio
OpenShift Service Mesh
How to mitigate CVE-2023-35944
Install updates from vendor's website.
envoy - addressed in versions 1.23.12, 1.24.10, 1.25.9, 1.26.4
Istio - addressed in versions 1.16.7, 1.17.5, 1.18.2
OpenShift Service Mesh - addressed in versions 2.2.10, 2.3.6, 2.4.2
Istio - addressed in versions 1.16.7, 1.17.5, 1.18.2
OpenShift Service Mesh - addressed in versions 2.2.10, 2.3.6, 2.4.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Envoy
- Multiple vulnerabilities in Istio
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.4
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.3
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- Amazon Linux AMI update for ecs-service-connect-agent
- Amazon Linux AMI update for ecs-service-connect-agent