MidnightBSD

Advisories for projectcontour

CVE-2020-15127 MEDIUM

In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flipping the readiness endpoint to false, which removes Envoy from the routing pool. When running Envoy (For example on the host network, pod spec hostNetwork=true), the shutdown manager's endpoint is accessible to anyone on the network that can reach the Kubernetes node that's running Envoy. There is no authentication in place that prevents a rogue actor on the network from shutting down Envoy via the shutdown manager endpoint. Successful exploitation of this issue will lead to bad actors shutting down all instances of Envoy, essentially killing the entire ingress data plane. This is fixed in version 1.7.0.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6
security-advisories@github.com 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-306,CWE-306,

Products Affected

Vendor Product Version
projectcontour contour *
CVE-2021-32783 MEDIUM

Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the Envoy container. This can be used to shut down Envoy remotely (a denial of service), or to expose the existence of any Secret that Envoy is using for its configuration, including most notably TLS Keypairs. However, it *cannot* be used to get the *content* of those secrets. Since this attack allows access to the administration interface, a variety of administration options are available, such as shutting down the Envoy or draining traffic. In general, the Envoy admin interface cannot easily be used for making changes to the cluster, in-flight requests, or backend services, but it could be used to shut down or drain Envoy, change traffic routing, or to retrieve secret metadata, as mentioned above. The issue will be addressed in Contour v1.18.0 and a cherry-picked patch release, v1.17.1, has been released to cover users who cannot upgrade at this time. For more details refer to the linked GitHub Security Advisory.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 8.5 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H 3.1 4.7
nvd@nist.gov 8.5 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H 3.1 4.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-441,CWE-610,

Products Affected

Vendor Product Version
projectcontour contour *
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
caddyserver caddy *
jenkins jenkins *
f5 big-ip_link_controller *
f5 big-ip_access_policy_manager 17.1.0
cisco unified_contact_center_domain_manager -
golang networking *
cisco unified_contact_center_management_portal -
f5 big-ip_application_visibility_and_reporting 17.1.0
redhat openshift_pipelines -
redhat openshift_container_platform 4.0
redhat openstack_platform 16.1
f5 nginx_plus r30
openresty openresty *
microsoft windows_11_21h2 *
cisco ultra_cloud_core_-_policy_control_function 2024.01.0
redhat web_terminal -
apache tomcat 11.0.0
redhat openshift_dev_spaces -
f5 big-ip_fraud_protection_service 17.1.0
cisco prime_infrastructure *
redhat jboss_enterprise_application_platform 7.0.0
redhat enterprise_linux 8.0
redhat cert-manager_operator_for_red_hat_openshift -
redhat openshift_gitops -
varnish_cache_project varnish_cache *
apache solr *
redhat jboss_enterprise_application_platform 6.0.0
microsoft windows_server_2022 -
redhat integration_camel_k -
grpc grpc *
dena h2o *
cisco ultra_cloud_core_-_serving_gateway_function *
redhat openshift_serverless -
fedoraproject fedora 38
f5 big-ip_policy_enforcement_manager *
linkerd linkerd 2.14.0
cisco telepresence_video_communication_server *
apache traffic_server *
nghttp2 nghttp2 *
debian debian_linux 11.0
f5 big-ip_application_acceleration_manager *
kazu-yamamoto http2 *
redhat self_node_remediation_operator -
cisco crosswork_zero_touch_provisioning *
redhat openstack_platform 17.1
traefik traefik *
redhat jboss_core_services -
fedoraproject fedora 37
f5 big-ip_ddos_hybrid_defender 17.1.0
f5 big-ip_policy_enforcement_manager 17.1.0
redhat fence_agents_remediation_operator -
redhat openshift -
amazon opensearch_data_prepper *
redhat integration_service_registry -
linecorp armeria *
redhat jboss_fuse 6.0.0
netapp oncommand_insight -
redhat jboss_fuse 7.0.0
f5 nginx_plus *
cisco secure_malware_analytics *
f5 big-ip_domain_name_system *
redhat enterprise_linux 9.0
redhat cost_management -
linkerd linkerd 2.13.1
golang go *
microsoft .net *
grpc grpc 1.57.0
f5 big-ip_advanced_firewall_manager 17.1.0
netapp astra_control_center -
cisco business_process_automation *
apache tomcat *
linkerd linkerd 2.13.0
f5 big-ip_advanced_web_application_firewall *
debian debian_linux 10.0
f5 big-ip_local_traffic_manager *
f5 big-ip_advanced_web_application_firewall 17.1.0
cisco connected_mobile_experiences *
linkerd linkerd 2.14.1
cisco unified_attendant_console_advanced -
f5 big-ip_ddos_hybrid_defender *
cisco fog_director *
redhat migration_toolkit_for_applications 6.0
cisco ios_xe *
apple swiftnio_http/2 *
netty netty *
redhat build_of_quarkus -
redhat ceph_storage 5.0
redhat service_interconnect 1.0
cisco ios_xr *
f5 big-ip_global_traffic_manager 17.1.0
projectcontour contour *
f5 big-ip_ssl_orchestrator 17.1.0
cisco iot_field_network_director *
f5 big-ip_websafe *
redhat integration_camel_for_spring_boot -
redhat jboss_a-mq_streams -
cisco prime_cable_provisioning *
facebook proxygen *
f5 big-ip_next_service_proxy_for_kubernetes *
cisco firepower_threat_defense *
redhat node_maintenance_operator -
f5 nginx_ingress_controller *
redhat process_automation 7.0
cisco crosswork_situation_manager -
redhat single_sign-on 7.0
microsoft windows_10_1809 *
konghq kong_gateway *
microsoft windows_10_21h2 *
redhat jboss_data_grid 7.0.0
redhat openshift_secondary_scheduler_operator -
redhat decision_manager 7.0
f5 big-ip_advanced_firewall_manager *
f5 big-ip_carrier-grade_nat 17.1.0
redhat advanced_cluster_security 3.0
cisco secure_dynamic_attributes_connector *
debian debian_linux 12.0
cisco crosswork_data_gateway *
cisco ultra_cloud_core_-_policy_control_function *
akka http_server *
redhat openshift_distributed_tracing -
microsoft windows_10_1607 *
redhat enterprise_linux 6.0
f5 big-ip_local_traffic_manager 17.1.0
f5 big-ip_analytics 17.1.0
redhat node_healthcheck_operator -
cisco nx-os *
cisco prime_access_registrar *
f5 big-ip_application_security_manager *
redhat openshift_service_mesh 2.0
redhat run_once_duration_override_operator -
golang http2 *
cisco enterprise_chat_and_email -
redhat advanced_cluster_management_for_kubernetes 2.0
f5 big-ip_webaccelerator *
redhat quay 3.0.0
redhat cryostat 2.0
redhat service_telemetry_framework 1.5
redhat certification_for_red_hat_enterprise_linux 8.0
envoyproxy envoy 1.26.4
cisco unified_contact_center_enterprise -
eclipse jetty *
redhat openshift_sandboxed_containers -
f5 big-ip_carrier-grade_nat *
nodejs node.js *
f5 nginx_plus r29
microsoft asp.net_core *
redhat jboss_a-mq 7
ietf http 2.0
redhat certification_for_red_hat_enterprise_linux 9.0
envoyproxy envoy 1.24.10
redhat satellite 6.0
f5 big-ip_webaccelerator 17.1.0
traefik traefik 3.0.0
f5 big-ip_global_traffic_manager *
f5 big-ip_domain_name_system 17.1.0
f5 big-ip_next 20.0.1
microsoft visual_studio_2022 *
redhat openstack_platform 16.2
cisco ultra_cloud_core_-_session_management_function *
redhat openshift_virtualization 4
microsoft windows_11_22h2 *
redhat openshift_data_science -
envoyproxy envoy 1.25.9
apache apisix *
cisco prime_network_registrar *
f5 big-ip_application_acceleration_manager 17.1.0
f5 big-ip_websafe 17.1.0
cisco expressway *
envoyproxy envoy 1.27.0
redhat migration_toolkit_for_containers -
f5 big-ip_ssl_orchestrator *
microsoft cbl-mariner *
redhat machine_deletion_remediation_operator -
f5 big-ip_fraud_protection_service *
redhat 3scale_api_management_platform 2.0
f5 big-ip_access_policy_manager *
redhat migration_toolkit_for_virtualization -
microsoft azure_kubernetes_service *
redhat ansible_automation_platform 2.0
redhat advanced_cluster_security 4.0
microsoft windows_server_2019 -
f5 big-ip_link_controller 17.1.0
cisco data_center_network_manager -
redhat build_of_optaplanner 8.0
cisco unified_contact_center_enterprise_-_live_data_server *
redhat openshift_developer_tools_and_services -
linkerd linkerd *
redhat network_observability_operator -
microsoft windows_10_22h2 *
cisco secure_web_appliance_firmware *
redhat logging_subsystem_for_red_hat_openshift -
f5 big-ip_application_security_manager 17.1.0
redhat support_for_spring_boot -
istio istio *
f5 big-ip_application_visibility_and_reporting *
f5 nginx *
f5 big-ip_analytics *
redhat openshift_api_for_data_protection -
redhat openshift_container_platform_assisted_installer -
microsoft windows_server_2016 -
cisco crosswork_data_gateway 5.0
CVE-2024-36539

Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Products Affected

Vendor Product Version
projectcontour contour 1.28.3
CVE-2026-41246

Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.routes[].cookieRewritePolicies[].pathRewrite.value or spec.routes[].services[].cookieRewritePolicies[].pathRewrite.value that results in arbitrary code execution in the Envoy proxy. The cookie rewriting feature is internally implemented using Envoy's HTTP Lua filter. User-controlled values are interpolated into Lua source code using Go text/template without sufficient sanitization. The injected code only executes when processing traffic on the attacker's own route, which they already control. However, since Envoy runs as shared infrastructure, the injected code can also read Envoy's xDS client credentials from the filesystem or cause denial of service for other tenants sharing the Envoy instance. This vulnerability is fixed in v1.33.4, v1.32.5, and v1.31.6.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H 2.8 5.2

Products Affected

Vendor Product Version
projectcontour contour *