CVE-2019-9900
Last modified
CVE-2019-9900 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.. EPSS estimates a 3.73% chance of exploitation in the next 30 days.
Description
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Envoyproxy | Envoy | <= 1.9.0 |
| Redhat | Openshift Service Mesh | All versions |
References
- https://access.redhat.com/errata/RHSA-2019:0741Third Party Advisory
- https://github.com/envoyproxy/envoy/issues/6434Exploit, Issue Tracking, Third Party Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-x74r-f4mw-c32hExploit, Mitigation, Third Party Advisory
- https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_historyRelease Notes, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0741Third Party Advisory
- https://github.com/envoyproxy/envoy/issues/6434Exploit, Issue Tracking, Third Party Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-x74r-f4mw-c32hExploit, Mitigation, Third Party Advisory
- https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_historyRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9900?
How severe is CVE-2019-9900?
How do I fix CVE-2019-9900?
Are you affected by CVE-2019-9900?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
