Input validation error in envoy - CVE-2024-45806
Published: September 20, 2024
Vulnerability identifier: #VU97625
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45806
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to software considers all RFC1918 private address ranges as internal. A remote attacker can manipulate Envoy headers and gain unauthorized access or perform other malicious actions within the mesh.
Affected software
envoy
Istio
OpenShift Service Mesh
Istio
OpenShift Service Mesh
How to mitigate CVE-2024-45806
Install updates from vendor's website.
envoy - addressed in versions 1.28.7, 1.29.9, 1.30.6, 1.31.2
Istio - addressed in versions 1.22.5, 1.23.2
OpenShift Service Mesh - addressed in versions 2.5.5, 2.6.2
Istio - addressed in versions 1.22.5, 1.23.2
OpenShift Service Mesh - addressed in versions 2.5.5, 2.6.2