VDB

CVE-2019-9901

CVE-2019-9901 PUBLISHED CVSS 6.5 MEDIUM

Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy.

EPSS 2.68% · 84.4th percentile

Risk Scores

CVSS 3.0
6.5
CVSS:3.0/AC:H/AV:N/A:L/C:L/I:L/PR:N/S:C/UI:N
EPSS Score
2.68%
84.4th percentile

Affected Products

VendorProductVersions
envoyproxyenvoy0
github.comenvoyproxy/envoy0
n/an/an/a

Timeline

  • Apr 25, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›