Back

CRITICAL

istio/envoy: Path traversal via URL Patch manipulation in HTTP/1.x header

Published Apr 25, 2019

Description

Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 25, 2019
Updated Aug 4, 2024
Reserved Mar 21, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 5, 2019
GHSA-2WMF-P7F8-W42H