PoC Index

CVE-2019-9900

HIGH 8.3EPSS 3.7%

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.

CVSS v3.1
8.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CVSS v3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.73% chance of exploitation in the next 30 days, 89th percentile
Published
2019-04-25
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related