Authorization bypass in Contour
Published Jul 23, 2021
8.5
HIGHCVSS 3.1
EPSS 1.15%
Description
Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the Envoy container. This can be used to shut down Envoy remotely (a denial of service), or to expose the existence of any Secret that Envoy is using for its configuration, including most notably TLS Keypairs. However, it *cannot* be used to get the *content* of those secrets. Since this attack allows access to the administration interface, a variety of administration options are available, such as shutting down the Envoy or draining traffic. In general, the Envoy admin interface cannot easily be used for making changes to the cluster, in-flight requests, or backend services, but it could be used to shut down or drain Envoy, change traffic routing, or to retrieve secret metadata, as mentioned above. The issue will be addressed in Contour v1.18.0 and a cherry-picked patch release, v1.17.1, has been released to cover users who cannot upgrade at this time. For more details refer to the linked GitHub Security Advisory.
Affected products
-
- Version < 1.17.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Projectcontour | Contour | n/a |
|
- < 1.17.1
No data.
No Red Hat product state for this CVE.
github.com/projectcontour/contour
Go
Introduced 1.15.0 Fixed 1.15.2github.com/projectcontour/contour
Go
Introduced 1.16.0 Fixed 1.16.1github.com/projectcontour/contour
Go
Introduced 1.17.0 Fixed 1.17.1github.com/projectcontour/contour
Go
Introduced 0 Fixed 1.14.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/projectcontour/contour | 1.15.0 | 1.15.2 |
| Go | github.com/projectcontour/contour | 1.16.0 | 1.16.1 |
| Go | github.com/projectcontour/contour | 1.17.0 | 1.17.1 |
| Go | github.com/projectcontour/contour | 0 | 1.14.2 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:P/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.15% (0.01151) | 65.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.15% (0.01151) | 62.65th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.27% (0.00265) | 47.97th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00097) | 42.18th | v3 (v2023.03.01) |
| Nov 15, 2023 | 0.10% (0.00097) | 40.26th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00094) | 38.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00890) | 30.33th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00890) | 26.62th | v2 (v2022.01.01) |
| Mar 31, 2022 | 5.37% (0.05372) | 76.79th | v2 (v2022.01.01) |
| Jan 6, 2022 | 4.49% (0.04486) | 74.80th | v1 |
| Jan 5, 2022 | 1.04% (0.01036) | 63.73th | v5 (v2026.06.15) |
| Jul 24, 2021 | 1.04% (0.01036) | 0.00th | v1 |
References (9)
- https://github.com/advisories/GHSA-5ph6-qq5x-7jwc Advisory
- https://github.com/projectcontour/contour/commit/5f3e6d0ab1d48e64bae46400c85c490b200393a3
- https://github.com/projectcontour/contour/commit/b53a5c4fd927f4ea2c6cf02f1359d8e28bef852e x_refsource_MISCPatchThird Party Advisory
- https://github.com/projectcontour/contour/releases/tag/v1.14.2
- https://github.com/projectcontour/contour/releases/tag/v1.15.2
- https://github.com/projectcontour/contour/releases/tag/v1.16.1
- https://github.com/projectcontour/contour/releases/tag/v1.17.1 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/projectcontour/contour/security/advisories/GHSA-5ph6-qq5x-7jwc x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-32783
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-5ph6-qq5x-7jwc | Advisory | |
| https://github.com/projectcontour/contour/commit/5f3e6d0ab1d48e64bae46400c85c490b200393a3 | ||
| https://github.com/projectcontour/contour/commit/b53a5c4fd927f4ea2c6cf02f1359d8e28bef852e | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/projectcontour/contour/releases/tag/v1.14.2 | ||
| https://github.com/projectcontour/contour/releases/tag/v1.15.2 | ||
| https://github.com/projectcontour/contour/releases/tag/v1.16.1 | ||
| https://github.com/projectcontour/contour/releases/tag/v1.17.1 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/projectcontour/contour/security/advisories/GHSA-5ph6-qq5x-7jwc | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-32783 |
Change history (0)
No recorded changes yet.