Use of Weak Credentials in envoy - CVE-2024-23326
Published: June 5, 2024
Vulnerability identifier: #VU91157
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23326
CWE-ID: CWE-1391
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the Envoy incorrectly accepts HTTP 200 response for entering upgrade mode. A remote attacker can gain access to sensitive information on the system.
Affected software
envoy
Amazon Linux AMI
Istio
OpenShift Service Mesh
Amazon Linux AMI
Istio
OpenShift Service Mesh
How to mitigate CVE-2024-23326
Install updates from vendor's website.
envoy - addressed in versions 1.27.6, 1.28.4, 1.29.5, 1.30.2
Istio - addressed in versions 1.20.7, 1.21.3, 1.22.1
OpenShift Service Mesh - update to 2.5.5
Istio - addressed in versions 1.20.7, 1.21.3, 1.22.1
OpenShift Service Mesh - update to 2.5.5