Vulnerability Name: | CVE-2020-11767 (CCN-180304) | ||||||||||||
Assigned: | 2019-05-01 | ||||||||||||
Published: | 2019-05-01 | ||||||||||||
Updated: | 2021-07-21 | ||||||||||||
Summary: | Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured explicitly (e.g., abc.example.com) is sent to the server(s) listening behind *.example.com. The outcome should instead be 421 Misdirected Request. Imagine a shared caching forward proxy re-using an HTTP/2 connection for a large subnet with many users. If a victim is interacting with abc.example.com, and a server (for abc.example.com) recycles the TCP connection to the forward proxy, the victim's browser may suddenly start sending sensitive data to a *.example.com server. This occurs because the forward proxy between the victim and the origin server reuses connections (which obeys the specification), but neither Istio nor Envoy corrects this by sending a 421 error. Similarly, this behavior voids the security model browsers have put in place between domains. | ||||||||||||
CVSS v3 Severity: | 3.1 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N) 2.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
6.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-11767 Source: MISC Type: Issue Tracking, Third Party Advisory https://bugs.chromium.org/p/chromium/issues/detail?id=954160#c5 Source: XF Type: UNKNOWN istio-cve202011767-info-disc(180304) Source: CCN Type: Envoy GIT Repository Envoy does not adhere to HTTP/2 RFC 7540 #6767 Source: MISC Type: Third Party Advisory https://github.com/envoyproxy/envoy/issues/6767 Source: CCN Type: Istio GIT Repository Istio does not adhere to HTTP/2 RFC 7540 #13589 Source: MISC Type: Exploit, Third Party Advisory https://github.com/istio/istio/issues/13589 Source: MISC Type: Third Party Advisory https://github.com/istio/istio/issues/9429 | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |