CVE-2024-23324: Envoy ext auth can be bypassed when Proxy protocol filter sets invalid UTF-8 metadata
Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to extauthz, circumventing extauthz checks when failuremodeallow is set to true. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
envoyproxy/envoyto a version that resolves this vulnerability.Fixed in 1.29.1 - Upgrade
Upgrade
envoyproxy/envoyto a version that resolves this vulnerability.Fixed in 1.28.1 - Upgrade
Upgrade
envoyproxy/envoyto a version that resolves this vulnerability.Fixed in 1.27.3 - Upgrade
Upgrade
envoyproxy/envoyto a version that resolves this vulnerability.Fixed in 1.26.7
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23324?
CVE-2024-23324 has been categorized with a high severity due to the potential for bypassing external authentication checks.
How do I fix CVE-2024-23324?
To mitigate CVE-2024-23324, update Envoy Proxy to a version above 1.29.1 and ensure that failure_mode_allow is set to false.
Which versions of Envoy Proxy are affected by CVE-2024-23324?
CVE-2024-23324 affects Envoy Proxy versions from 1.26.0 to 1.26.7, 1.27.0 to 1.27.3, 1.28.0 to 1.28.1, and 1.29.0 to 1.29.1.
What type of vulnerability is CVE-2024-23324?
CVE-2024-23324 is a security vulnerability that allows external authentication to be bypassed by malformed gRPC requests.
Who is affected by CVE-2024-23324?
Organizations using vulnerable versions of Envoy Proxy that rely on external authentication for security are at risk from CVE-2024-23324.