Envoy Vulnerability: Unvalidated 'REQUESTED_SERVER_NAME' Field Leads to Log Injection
CVE-2024-45808

6.5MEDIUM

Key Information:

Vendor

Envoy

Status
Vendor
CVE Published:
20 September 2024

What is CVE-2024-45808?

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is achieved by exploiting the lack of validation for the REQUESTED_SERVER_NAME field for access loggers. This issue has been addressed in versions 1.31.2, 1.30.6, 1.29.9, and 1.28.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-45808 : Envoy Vulnerability: Unvalidated 'REQUESTED_SERVER_NAME' Field Leads to Log Injection