CVE-2019-9900

CVE-2019-9900

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.

Source: CVE-2019-9900

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다