Envoy vulnerable to OAuth2 credentials exploit with permanent validity
Published Jul 25, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.81%
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, a malicious client is able to construct credentials with permanent validity in some specific scenarios. This is caused by the some rare scenarios in which HMAC payload can be always valid in OAuth2 filter's check. Versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12 have a fix for this issue. As a workaround, avoid wildcards/prefix domain wildcards in the host's domain configuration.
Affected products
-
Affected
- < 1.23.12
- ≥ 1.24.0, < 1.24.10
- ≥ 1.25.0, < 1.25.9
- ≥ 1.26.0, < 1.26.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Envoyproxy | Envoy | unknown | Affected
|
- ≥ 1.23.0 · < 1.23.12
- ≥ 1.24.0 · < 1.24.10
- ≥ 1.25.0 · < 1.25.9
- ≥ 1.26.0 · < 1.26.4
No data.
Red Hat OpenShift Service Mesh 2.2 for RHEL 8
openshift-service-mesh/proxyv2-rhel8:2.2.10-3
Fixed · RHSA-2023:5175
Red Hat OpenShift Service Mesh 2.3 for RHEL 8
openshift-service-mesh/proxyv2-rhel8:2.3.6-4
Fixed · RHSA-2023:4624
Red Hat OpenShift Service Mesh 2.4 for RHEL 8
openshift-service-mesh/proxyv2-rhel8:2.4.2-7
Fixed · RHSA-2023:4625
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Service Mesh 2.2 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8:2.2.10-3 | Fixed | RHSA-2023:5175 |
| Red Hat OpenShift Service Mesh 2.3 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8:2.3.6-4 | Fixed | RHSA-2023:4624 |
| Red Hat OpenShift Service Mesh 2.4 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8:2.4.2-7 | Fixed | RHSA-2023:4625 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2023-35941 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2217977 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-39925 Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-7mhv-gr67-hq55 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-35941
- https://www.cve.org/CVERecord?id=CVE-2023-35941
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-35941 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2217977 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-39925 | Advisory | |
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-7mhv-gr67-hq55 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-35941 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-35941 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data