PT-2025-4041 · Red Hat · Openshift Service Mesh

Antony Di Scala

+1

·

Published

2025-01-28

·

Updated

2025-01-28

·

CVE-2025-0754

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenShift Service Mesh versions 2.5.6 through 2.6.3
Description The issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can mislead logging mechanisms, enabling attackers to manipulate log entries or execute reflected cross-site scripting (XSS) attacks.
Recommendations For OpenShift Service Mesh version 2.5.6, update to a version that properly sanitizes HTTP headers. For OpenShift Service Mesh version 2.6.3, update to a version that properly sanitizes HTTP headers. As a temporary workaround, consider restricting access to the x-forwarded-for header to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-0754

Affected Products

Openshift Service Mesh