在线时间:8:00-16:00
迪恩网络APP
随时随地掌握行业动态
扫描二维码
关注迪恩网络微信公众号
CVE-2019-9901Istio Proxy 安全漏洞 发布时间:2019-04-11类型:CANstatus:Candidatephase:Assigned数据库:HTTP 漏洞描述Envoy是一款开源的分布式代理服务器。 Envoy 1.9.0及之前版本中存在访问控制错误漏洞。攻击者可利用该漏洞绕过访问控制。Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy. 参考文献
|
2023-10-27
2022-08-15
2022-08-17
2022-09-23
2022-08-13
请发表评论