CVE-2024-7207

Public on 2024-09-19
Modified on 2025-02-06
Description
A flaw was found in Envoy. It is possible to modify or manipulate headers from external clients when pass-through routes are used for the ingress gateway. This issue could allow a malicious user to forge what is logged by Envoy as a requested path and cause the Envoy proxy to make requests to internal-only services or arbitrary external systems. This is a regression of the fix for CVE-2023-27487.
Severity
Important severity
Important
CVSS v3 Base Score
8.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 2 - Ecs Extra ecs-service-connect-agent Not Affected
HAQM Linux 2023 ecs-service-connect-agent Not Affected

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N