← Back

CVE-2019-9900

nvd nist
Published: Apr 25, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.7
Source: NVD

Description

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.

Affected (2)

1 product
Envoy
1 product
Openshift Service Mesh
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.9.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (10)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory
Source: cve@mitre.org
ExploitMitigationThird Party Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.