PT-2024-38168 · Envoy · Envoy

Published

2024-09-19

·

Updated

2024-12-17

·

CVE-2024-7207

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Envoy (affected versions not specified)
Description A flaw was found in Envoy, allowing modification or manipulation of headers from external clients when pass-through routes are used for the ingress gateway. This issue could enable a malicious user to forge the requested path logged by Envoy, causing the Envoy proxy to make requests to internal-only services or arbitrary external systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

BIT-ENVOY-2024-7207
CVE-2024-7207

Affected Products

Envoy