CVE-2019-9900
Summary
| CVE | CVE-2019-9900 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-25 15:29:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Envoyproxy | Envoy | All | All | All | All |
| Application | Redhat | Openshift Service Mesh | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Version history — envoy tag-v1.9.1 documentation | CONFIRM | www.envoyproxy.io | Release Notes, Vendor Advisory |
| NUL characters in HTTP/1 headers allow access control bypass (CVE-2019-9900) · Advisory · envoyproxy/envoy · GitHub | CONFIRM | github.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Google Groups | CONFIRM | groups.google.com | Third Party Advisory |
| CVE-2019-9900 · Issue #6434 · envoyproxy/envoy · GitHub | CONFIRM | github.com | Exploit, Issue Tracking, Third Party Advisory |
| Google Groups | groups.google.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.