PT-2024-38168 · Envoy · Envoy
Published
2024-09-19
·
Updated
2024-12-17
·
CVE-2024-7207
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Envoy (affected versions not specified)
Description
A flaw was found in Envoy, allowing modification or manipulation of headers from external clients when pass-through routes are used for the ingress gateway. This issue could enable a malicious user to forge the requested path logged by Envoy, causing the Envoy proxy to make requests to internal-only services or arbitrary external systems.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Envoy