MidnightBSD

Advisories for projectcontour

CVE-2020-15127 MEDIUM

In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flipping the readiness endpoint to false, which removes Envoy from the routing pool. When running Envoy (For example on the host network, pod spec hostNetwork=true), the shutdown manager's endpoint is accessible to anyone on the network that can reach the Kubernetes node that's running Envoy. There is no authentication in place that prevents a rogue actor on the network from shutting down Envoy via the shutdown manager endpoint. Successful exploitation of this issue will lead to bad actors shutting down all instances of Envoy, essentially killing the entire ingress data plane. This is fixed in version 1.7.0.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-306,CWE-306,

Products Affected

Vendor Product Version
projectcontour contour *
CVE-2021-32783 MEDIUM

Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the Envoy container. This can be used to shut down Envoy remotely (a denial of service), or to expose the existence of any Secret that Envoy is using for its configuration, including most notably TLS Keypairs. However, it *cannot* be used to get the *content* of those secrets. Since this attack allows access to the administration interface, a variety of administration options are available, such as shutting down the Envoy or draining traffic. In general, the Envoy admin interface cannot easily be used for making changes to the cluster, in-flight requests, or backend services, but it could be used to shut down or drain Envoy, change traffic routing, or to retrieve secret metadata, as mentioned above. The issue will be addressed in Contour v1.18.0 and a cherry-picked patch release, v1.17.1, has been released to cover users who cannot upgrade at this time. For more details refer to the linked GitHub Security Advisory.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 8.5 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H 3.1 4.7
nvd@nist.gov 8.5 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H 3.1 4.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-441,CWE-610,

Products Affected

Vendor Product Version
projectcontour contour *
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
redhat node_maintenance_operator -
f5 big-ip_local_traffic_manager 17.1.0
cisco ios_xe *
apple swiftnio_http/2 *
dena h2o *
redhat openshift_distributed_tracing -
redhat jboss_core_services -
f5 nginx_plus r30
redhat run_once_duration_override_operator -
redhat certification_for_red_hat_enterprise_linux 9.0
microsoft windows_server_2022 -
redhat openstack_platform 17.1
redhat advanced_cluster_management_for_kubernetes 2.0
redhat openshift -
debian debian_linux 12.0
kazu-yamamoto http2 *
envoyproxy envoy 1.25.9
f5 big-ip_advanced_firewall_manager 17.1.0
f5 big-ip_application_visibility_and_reporting *
f5 big-ip_application_acceleration_manager *
traefik traefik 3.0.0
redhat jboss_a-mq_streams -
redhat openshift_data_science -
microsoft azure_kubernetes_service *
redhat logging_subsystem_for_red_hat_openshift -
f5 big-ip_ssl_orchestrator *
grpc grpc *
f5 big-ip_next_service_proxy_for_kubernetes *
f5 big-ip_domain_name_system 17.1.0
cisco expressway *
jenkins jenkins *
linkerd linkerd 2.14.0
f5 big-ip_analytics 17.1.0
f5 nginx *
f5 big-ip_fraud_protection_service 17.1.0
cisco unified_contact_center_enterprise -
redhat process_automation 7.0
microsoft windows_server_2016 -
f5 big-ip_local_traffic_manager *
microsoft asp.net_core *
f5 big-ip_carrier-grade_nat 17.1.0
redhat machine_deletion_remediation_operator -
f5 big-ip_link_controller 17.1.0
f5 big-ip_link_controller *
redhat decision_manager 7.0
f5 nginx_ingress_controller *
redhat openshift_api_for_data_protection -
cisco ultra_cloud_core_-_policy_control_function *
envoyproxy envoy 1.24.10
redhat openshift_container_platform_assisted_installer -
traefik traefik *
microsoft windows_server_2019 -
nghttp2 nghttp2 *
redhat cost_management -
redhat openshift_dev_spaces -
redhat 3scale_api_management_platform 2.0
projectcontour contour *
f5 nginx_plus r29
redhat migration_toolkit_for_virtualization -
redhat integration_camel_k -
cisco firepower_threat_defense *
amazon opensearch_data_prepper *
redhat jboss_enterprise_application_platform 6.0.0
redhat openshift_sandboxed_containers -
f5 big-ip_websafe *
konghq kong_gateway *
linkerd linkerd *
redhat self_node_remediation_operator -
golang go *
redhat openshift_service_mesh 2.0
f5 big-ip_policy_enforcement_manager *
microsoft windows_10_1809 *
cisco telepresence_video_communication_server *
redhat enterprise_linux 8.0
apache solr *
redhat support_for_spring_boot -
debian debian_linux 10.0
redhat cert-manager_operator_for_red_hat_openshift -
cisco business_process_automation *
linecorp armeria *
redhat openstack_platform 16.2
f5 big-ip_access_policy_manager 17.1.0
redhat advanced_cluster_security 4.0
linkerd linkerd 2.14.1
f5 big-ip_application_visibility_and_reporting 17.1.0
redhat build_of_quarkus -
redhat ceph_storage 5.0
cisco secure_dynamic_attributes_connector *
cisco enterprise_chat_and_email -
facebook proxygen *
redhat jboss_enterprise_application_platform 7.0.0
cisco crosswork_data_gateway 5.0
microsoft cbl-mariner *
redhat network_observability_operator -
redhat node_healthcheck_operator -
f5 big-ip_domain_name_system *
netapp astra_control_center -
f5 nginx_plus *
apache traffic_server *
cisco crosswork_data_gateway *
redhat jboss_fuse 7.0.0
cisco data_center_network_manager -
cisco prime_access_registrar *
microsoft windows_10_1607 *
cisco ultra_cloud_core_-_session_management_function *
cisco ios_xr *
cisco ultra_cloud_core_-_serving_gateway_function *
redhat openshift_serverless -
cisco unified_contact_center_management_portal -
redhat openshift_pipelines -
microsoft windows_11_22h2 *
golang networking *
redhat migration_toolkit_for_applications 6.0
envoyproxy envoy 1.26.4
f5 big-ip_ssl_orchestrator 17.1.0
f5 big-ip_global_traffic_manager 17.1.0
linkerd linkerd 2.13.0
cisco ultra_cloud_core_-_policy_control_function 2024.01.0
fedoraproject fedora 38
redhat fence_agents_remediation_operator -
cisco connected_mobile_experiences *
redhat openshift_gitops -
debian debian_linux 11.0
golang http2 *
cisco unified_contact_center_domain_manager -
redhat cryostat 2.0
cisco unified_contact_center_enterprise_-_live_data_server *
f5 big-ip_ddos_hybrid_defender *
redhat service_interconnect 1.0
caddyserver caddy *
f5 big-ip_fraud_protection_service *
istio istio *
redhat jboss_fuse 6.0.0
f5 big-ip_next 20.0.1
microsoft visual_studio_2022 *
redhat ansible_automation_platform 2.0
redhat enterprise_linux 6.0
cisco crosswork_zero_touch_provisioning *
redhat integration_service_registry -
f5 big-ip_analytics *
cisco secure_malware_analytics *
redhat build_of_optaplanner 8.0
redhat openshift_developer_tools_and_services -
linkerd linkerd 2.13.1
redhat openstack_platform 16.1
redhat certification_for_red_hat_enterprise_linux 8.0
cisco prime_infrastructure *
redhat jboss_a-mq 7
redhat integration_camel_for_spring_boot -
f5 big-ip_webaccelerator 17.1.0
redhat service_telemetry_framework 1.5
microsoft windows_11_21h2 *
cisco secure_web_appliance_firmware *
f5 big-ip_websafe 17.1.0
eclipse jetty *
microsoft windows_10_21h2 *
netty netty *
microsoft .net *
redhat migration_toolkit_for_containers -
redhat enterprise_linux 9.0
openresty openresty *
apache tomcat *
fedoraproject fedora 37
f5 big-ip_application_security_manager 17.1.0
f5 big-ip_webaccelerator *
cisco nx-os *
f5 big-ip_advanced_web_application_firewall 17.1.0
cisco iot_field_network_director *
redhat advanced_cluster_security 3.0
redhat satellite 6.0
cisco prime_cable_provisioning *
cisco fog_director *
nodejs node.js *
cisco crosswork_situation_manager -
redhat openshift_virtualization 4
cisco unified_attendant_console_advanced -
f5 big-ip_advanced_web_application_firewall *
cisco prime_network_registrar *
f5 big-ip_application_acceleration_manager 17.1.0
f5 big-ip_advanced_firewall_manager *
f5 big-ip_access_policy_manager *
f5 big-ip_policy_enforcement_manager 17.1.0
microsoft windows_10_22h2 *
redhat single_sign-on 7.0
redhat jboss_data_grid 7.0.0
f5 big-ip_application_security_manager *
redhat openshift_secondary_scheduler_operator -
redhat web_terminal -
ietf http 2.0
redhat quay 3.0.0
redhat openshift_container_platform 4.0
apache apisix *
apache tomcat 11.0.0
f5 big-ip_carrier-grade_nat *
grpc grpc 1.57.0
f5 big-ip_ddos_hybrid_defender 17.1.0
netapp oncommand_insight -
envoyproxy envoy 1.27.0
akka http_server *
varnish_cache_project varnish_cache *
f5 big-ip_global_traffic_manager *
CVE-2024-36539

Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Products Affected

Vendor Product Version
projectcontour contour 1.28.3
CVE-2026-41246

Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.routes[].cookieRewritePolicies[].pathRewrite.value or spec.routes[].services[].cookieRewritePolicies[].pathRewrite.value that results in arbitrary code execution in the Envoy proxy. The cookie rewriting feature is internally implemented using Envoy's HTTP Lua filter. User-controlled values are interpolated into Lua source code using Go text/template without sufficient sanitization. The injected code only executes when processing traffic on the attacker's own route, which they already control. However, since Envoy runs as shared infrastructure, the injected code can also read Envoy's xDS client credentials from the filesystem or cause denial of service for other tenants sharing the Envoy instance. This vulnerability is fixed in v1.33.4, v1.32.5, and v1.31.6.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H 2.8 5.2

Products Affected

Vendor Product Version
projectcontour contour *