VulnerabilityModified
CVE-2019-9901
A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin.
CRITICAL 10.0EPSS 4.95%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy.
- CVSS 3.0
- 10.0 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 4.95% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-706
- Affected
- envoyproxy/envoy
- Source
- cve@mitre.org
References
- https://github.com/envoyproxy/envoy/issues/6435Issue Tracking, Mitigation, Third Party Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-xcx5-93pw-jw2w
- https://groups.google.com/forum/#%21topic/envoy-announce/VoHfnDqZiAM
- https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_historyRelease Notes, Vendor Advisory
- https://github.com/envoyproxy/envoy/issues/6435Issue Tracking, Mitigation, Third Party Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-xcx5-93pw-jw2w
- https://groups.google.com/forum/#%21topic/envoy-announce/VoHfnDqZiAM
- https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_historyRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.