Bug 1996934 (CVE-2021-32779) - CVE-2021-32779 envoyproxy/envoy: HTTP request with a URL fragment in the URI can bypass authorization policies
Summary: CVE-2021-32779 envoyproxy/envoy: HTTP request with a URL fragment in the URI ...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-32779
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1996910
TreeView+ depends on / blocked
 
Reported: 2021-08-24 03:36 UTC by Mark Cooper
Modified: 2023-09-01 01:22 UTC (History)
5 users (show)

Fixed In Version: envoyproxy/envoy 1.19.1, envoyproxy/envoy 1.18.4, envoyproxy/envoy 1.17.4, envoyrproxy/envoy 1.16.5
Doc Type: If docs needed, set a value
Doc Text:
An authorization bypass vulnerability was found in envoyproxy/envoy. When a URI path-based authorization policy is specified, envoy incorrectly evaluates the HTTP request which contains a URI #fragment. This flaw allows an attacker to bypass the authorization policy and access downstream services. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Clone Of:
Environment:
Last Closed: 2021-08-25 15:35:06 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2021:3272 0 None None None 2021-08-25 09:35:33 UTC
Red Hat Product Errata RHSA-2021:3273 0 None None None 2021-08-25 09:34:46 UTC

Description Mark Cooper 2021-08-24 03:36:21 UTC
Envoy proxy through 1.19.1 contains a vulnerability where a HTTP request with a fragment in the URI can bypass authorization policies.

Comment 2 errata-xmlrpc 2021-08-25 09:34:44 UTC
This issue has been addressed in the following products:

  OpenShift Service Mesh 1.1

Via RHSA-2021:3273 https://access.redhat.com/errata/RHSA-2021:3273

Comment 3 errata-xmlrpc 2021-08-25 09:35:31 UTC
This issue has been addressed in the following products:

  OpenShift Service Mesh 2.0

Via RHSA-2021:3272 https://access.redhat.com/errata/RHSA-2021:3272

Comment 4 Product Security DevOps Team 2021-08-25 15:35:06 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-32779


Note You need to log in before you can comment on or make changes to this bug.