Related Vulnerabilities: CVE-2022-29226  

A flaw was found in Envoy. The OAuth filter does not include an implementation for validating access tokens, allowing remote attackers to bypass authentication to Envoy by providing any token value.

Description

A flaw was found in Envoy. The OAuth filter does not include an implementation for validating access tokens, allowing remote attackers to bypass authentication to Envoy by providing any token value.

Mitigation

There is no known mitigation for this flaw.

Additional Information

  • Bugzilla 2088739: CVE-2022-29226 envoy: oauth filter allows trivial bypass
  • CWE-303: Incorrect Implementation of Authentication Algorithm
  • FAQ: Frequently asked questions about CVE-2022-29226