CVE-2019-9900
This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
- CVSS 3.1
- 8.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
- EPSS
- 3.73% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- envoyproxy/envoy · redhat/openshift service mesh
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2019:0741Third Party Advisory
- https://github.com/envoyproxy/envoy/issues/6434Exploit, Issue Tracking, Third Party Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-x74r-f4mw-c32hExploit, Mitigation, Third Party Advisory
- https://groups.google.com/forum/#%21topic/envoy-announce/VoHfnDqZiAM
- https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_historyRelease Notes, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0741Third Party Advisory
- https://github.com/envoyproxy/envoy/issues/6434Exploit, Issue Tracking, Third Party Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-x74r-f4mw-c32hExploit, Mitigation, Third Party Advisory
- https://groups.google.com/forum/#%21topic/envoy-announce/VoHfnDqZiAM
- https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_historyRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.