Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23324


Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_authz checks when failure_mode_allow is set to true. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.


Published

2024-02-09T23:15:09.223

Last Modified

2024-11-21T08:57:30.563

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application envoyproxy envoy < 1.26.7 Yes
Application envoyproxy envoy < 1.27.3 Yes
Application envoyproxy envoy < 1.28.1 Yes
Application envoyproxy envoy < 1.29.1 Yes

References