216.73.216.36

CVE-2024-45808

· Published 20/09/2024 00:15 · Modified 25/09/2024 17:18

Labels: CVE-2024-45808 2024-09-20CVE-2024-45808CWE-116CWE-117[email protected]

Essential information

Published
20/09/2024 00:15
Modified
25/09/2024 17:18
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is achieved by exploiting the lack of validation for the `REQUESTED_SERVER_NAME` field for access loggers. This issue has been addressed in versions 1.31.2, 1.30.6, 1.29.9, and 1.28.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
envoyproxy / envoy cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
envoyproxy / envoy cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
envoyproxy / envoy cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
envoyproxy / envoy cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*

References