CVE-2021-32777

Related Vulnerabilities: CVE-2021-32777  

An authorization bypass vulnerability was found in envoyproxy/envoy. Envoy incorrectly evaluates an HTTP request with multiple `value` headers. This flaw allows an attacker to bypass rule policies that use the `ext_authz` extension. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Description

An authorization bypass vulnerability was found in envoyproxy/envoy. Envoy incorrectly evaluates an HTTP request with multiple `value` headers. This flaw allows an attacker to bypass rule policies that use the `ext_authz` extension. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Additional Information

  • Bugzilla 1996933: CVE-2021-32777 envoyproxy/envoy: HTTP request with multiple value headers can bypass authorization policies
  • CWE-863: Incorrect Authorization
  • FAQ: Frequently asked questions about CVE-2021-32777