CVE-2019-9900: High severity envoy proxy vulnerability
A flaw was found in Envoy 1.9.0 and older. When parsing HTTP/1.x header values, Envoy does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
Upstream issue:
https://github.com/envoyproxy/envoy/issues/6434
References:
https://istio.io/blog/2019/announcing-1.1.2/
Other sources
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9900?
CVE-2019-9900 is a vulnerability in Envoy 1.9.0 and earlier that allows remote attackers to potentially bypass header matching rules.
How does CVE-2019-9900 affect EnvoyProxy Envoy?
CVE-2019-9900 affects EnvoyProxy Envoy versions up to and including 1.9.0.
What is the severity of CVE-2019-9900?
CVE-2019-9900 has a severity rating of 8.3 (high).
How can remote attackers exploit CVE-2019-9900?
Remote attackers can craft header values with embedded NUL characters to potentially bypass header matching rules and gain unauthorized access to resources.
How can I fix CVE-2019-9900 vulnerability?
To fix the CVE-2019-9900 vulnerability, upgrade EnvoyProxy Envoy to a version later than 1.9.0.