BIT-envoy-gateway-2025-24030

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/envoy-gateway/BIT-envoy-gateway-2025-24030.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-envoy-gateway-2025-24030
Aliases
Published
2025-09-09T05:37:52.094Z
Modified
2025-09-09T06:44:28.526194Z
Summary
Envoy Admin Interface Exposed through prometheus metrics endpoint
Details

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the EnvoyProxy API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.

Database specific
{
    "cpes": [
        "cpe:2.3:a:envoyproxy:gateway:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / envoy-gateway

Package

Name
envoy-gateway
Purl
pkg:bitnami/envoy-gateway

Severity

  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.6