PT-2025-5269 · Unknown+1 · Envoy Gateway+1

Guydc

·

Published

2025-01-23

·

Updated

2025-09-09

·

CVE-2025-24030

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy Gateway versions prior to 1.2.6
Description A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by Envoy Gateway. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration, which may contain confidential data. The EnvoyProxy API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint, such as the "/stats/prometheus" endpoint. For example, the following command can be used to get the configuration dump of the proxy: curl --path-as-is http://<Proxy-Service-ClusterIP>:19001/stats/prometheus/../../config dump.
Recommendations For versions prior to 1.2.6, update to version 1.2.6 to fix the issue. As a temporary workaround, consider using the EnvoyProxy API to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Restrict access to the /stats/prometheus endpoint to minimize the risk of exploitation. Apply a bootstrap config patch, such as the provided JSONPatch example, to restrict access to the prometheus stats endpoint.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-ENVOY-GATEWAY-2025-24030
CVE-2025-24030
GHSA-J777-63HF-HX76
GO-2025-3418
OPENSUSE-SU-2025:14710-1
OPENSUSE-SU-2025_0297-1
SUSE-SU-2025:0297-1

Affected Products

Envoy Gateway
Suse