Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-9901
HistoryApr 25, 2019 - 4:29 p.m.

Improper access control

2019-04-2516:29:00
PRIOn knowledge base
www.prio-n.com
6

AI Score

9.3

Confidence

High

EPSS

0.004

Percentile

72.2%

Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/…/admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy.

AI Score

9.3

Confidence

High

EPSS

0.004

Percentile

72.2%