PT-2025-4041 · Red Hat · Openshift Service Mesh
Antony Di Scala
+1
·
Published
2025-01-28
·
Updated
2025-01-28
·
CVE-2025-0754
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenShift Service Mesh versions 2.5.6 through 2.6.3
Description
The issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the
x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can mislead logging mechanisms, enabling attackers to manipulate log entries or execute reflected cross-site scripting (XSS) attacks.Recommendations
For OpenShift Service Mesh version 2.5.6, update to a version that properly sanitizes HTTP headers.
For OpenShift Service Mesh version 2.6.3, update to a version that properly sanitizes HTTP headers.
As a temporary workaround, consider restricting access to the
x-forwarded-for header to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift Service Mesh