Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/envoyproxy/envoy: CVE-2024-7207 #3144

Closed
GoVulnBot opened this issue Sep 20, 2024 · 1 comment
Closed
Assignees
Labels
excluded: NOT_GO_CODE This vulnerability does not refer to a Go module. triaged

Comments

@GoVulnBot
Copy link

Advisory CVE-2024-7207 references a vulnerability in the following Go modules:

Module
github.com/envoyproxy/envoy

Description:
A flaw was found in Envoy. It is possible to modify or manipulate headers from external clients when pass-through routes are used for the ingress gateway. This issue could allow a malicious user to forge what is logged by Envoy as a requested path and cause the Envoy proxy to make requests to internal-only services or arbitrary external systems. This is a regression of the fix for CVE-2023-27487.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/envoyproxy/envoy
      vulnerable_at: 1.31.2
summary: CVE-2024-7207 in github.com/envoyproxy/envoy
cves:
    - CVE-2024-7207
references:
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-7207
    - web: https://access.redhat.com/security/cve/CVE-2024-7207
    - web: https://bugzilla.redhat.com/show_bug.cgi?id=2300352
    - web: https://github.com/envoyproxy/envoy/security/advisories/GHSA-ffhv-fvxq-r6mf
source:
    id: CVE-2024-7207
    created: 2024-09-20T00:01:25.199002667Z
review_status: UNREVIEWED

@zpavlinovic zpavlinovic self-assigned this Sep 20, 2024
@zpavlinovic zpavlinovic added excluded: NOT_GO_CODE This vulnerability does not refer to a Go module. and removed possibly not Go labels Sep 20, 2024
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/614715 mentions this issue: data/excluded: add 6 reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
excluded: NOT_GO_CODE This vulnerability does not refer to a Go module. triaged
Projects
None yet
Development

No branches or pull requests

3 participants