VDB
CVE-2025-24030
CVE-2025-24030
PUBLISHED
Envoy Admin Interface Exposed through prometheus metrics endpoint
EPSS 0.18% · 39.6th percentile
Risk Scores
EPSS Score
0.18%
39.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | envoy-gateway | 0, 0 |
| Bitnami | envoy-gateway | 0 |
Exploit Intelligence
- CIRCL seen: CVE-2025-24030 (circl-sighting)
- CIRCL seen: CVE-2025-24030 (circl-sighting)
- CIRCL published-proof-of-concept: CVE-2025-24030 (circl-sighting)
- CIRCL published-proof-of-concept: CVE-2025-24030 (circl-sighting)
- CIRCL published-proof-of-concept: CVE-2025-24030 (circl-sighting)
- https://github.com/envoyproxy/gateway/security/advisories/GHSA-j777-63hf-hx76 (circl)
- https://github.com/envoyproxy/gateway/commit/3eb3301ab3dbf12b201b47bdb6074d1233be07bd (circl)
- https://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/edge (circl)
- https://www.envoyproxy.io/docs/envoy/latest/operations/admin (circl)
Timeline
- Jan 21, 1970 Security Advisory
- Jan 23, 2025 CVE Published
- Jan 23, 2025 EPSS Score
- Jan 23, 2025 PoC Published
- Jan 23, 2025 PoC Published
- Jan 23, 2025 PoC Published
- Jan 23, 2025 PoC Published
- Jan 23, 2025 PoC Published
- Feb 7, 2025 EPSS Score
- Feb 22, 2025 EPSS Score
- Mar 3, 2025 Coalition ESS Score
- Mar 10, 2025 EPSS Score
References
- https://github.com/envoyproxy/gateway/commit/3eb3301ab3dbf12b201b47bdb6074d1233be07bd url
- https://github.com/envoyproxy/gateway/security/advisories/GHSA-j777-63hf-hx76 url
- https://nvd.nist.gov/vuln/detail/CVE-2025-24030 url
- https://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/edge url
- https://www.envoyproxy.io/docs/envoy/latest/operations/admin url