CVE-2019-18802

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
envoyproxyenvoy
𝑥
≤ 1.12.1
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libnghttp2-14
suse enterprise desktop 15 SP1
1.40.0-3.6.3
fixed
suse enterprise desktop 15 SP2
1.40.0-1.15
fixed
suse enterprise desktop 15 SP3
1.40.0-3.5.1
fixed
suse enterprise desktop 15 SP4
1.40.0-6.1
fixed
suse enterprise desktop 15 SP5
1.40.0-6.1
fixed
suse enterprise desktop 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise desktop 15 SP7
1.64.0-150700.1.5
fixed
suse enterprise sap 15 SP1
1.40.0-3.6.3
fixed
suse enterprise sap 15 SP2
1.40.0-1.15
fixed
suse enterprise sap 15 SP3
1.40.0-3.5.1
fixed
suse enterprise sap 15 SP4
1.40.0-6.1
fixed
suse enterprise sap 15 SP5
1.40.0-6.1
fixed
suse enterprise sap 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise sap 15 SP7
1.64.0-150700.1.5
fixed
suse enterprise server 15 SP1
1.40.0-3.6.3
fixed
suse enterprise server 15 SP2
1.40.0-1.15
fixed
suse enterprise server 15 SP3
1.40.0-3.5.1
fixed
suse enterprise server 15 SP4
1.40.0-6.1
fixed
suse enterprise server 15 SP5
1.40.0-6.1
fixed
suse enterprise server 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise server 15 SP7
1.64.0-150700.1.5
fixed
libnghttp2-14-32bit
suse enterprise desktop 15 SP1
1.40.0-3.6.3
fixed
suse enterprise desktop 15 SP2
1.40.0-1.15
fixed
suse enterprise desktop 15 SP3
1.40.0-3.5.1
fixed
suse enterprise desktop 15 SP4
1.40.0-6.1
fixed
suse enterprise desktop 15 SP5
1.40.0-6.1
fixed
suse enterprise desktop 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise desktop 15 SP7
1.64.0-150700.1.5
fixed
suse enterprise sap 15 SP1
1.40.0-3.6.3
fixed
suse enterprise sap 15 SP2
1.40.0-1.15
fixed
suse enterprise sap 15 SP3
1.40.0-3.5.1
fixed
suse enterprise sap 15 SP4
1.40.0-6.1
fixed
suse enterprise sap 15 SP5
1.40.0-6.1
fixed
suse enterprise sap 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise sap 15 SP7
1.64.0-150700.1.5
fixed
suse enterprise server 15 SP1
1.40.0-3.6.3
fixed
suse enterprise server 15 SP2
1.40.0-1.15
fixed
suse enterprise server 15 SP3
1.40.0-3.5.1
fixed
suse enterprise server 15 SP4
1.40.0-6.1
fixed
suse enterprise server 15 SP5
1.40.0-6.1
fixed
suse enterprise server 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise server 15 SP7
1.64.0-150700.1.5
fixed
libnghttp2-devel
suse enterprise desktop 15 SP1
1.40.0-3.6.3
fixed
suse enterprise desktop 15 SP2
1.40.0-1.15
fixed
suse enterprise desktop 15 SP3
1.40.0-3.5.1
fixed
suse enterprise desktop 15 SP4
1.40.0-6.1
fixed
suse enterprise desktop 15 SP5
1.40.0-6.1
fixed
suse enterprise desktop 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise desktop 15 SP7
1.64.0-150700.1.5
fixed
suse enterprise sap 15 SP1
1.40.0-3.6.3
fixed
suse enterprise sap 15 SP2
1.40.0-1.15
fixed
suse enterprise sap 15 SP3
1.40.0-3.5.1
fixed
suse enterprise sap 15 SP4
1.40.0-6.1
fixed
suse enterprise sap 15 SP5
1.40.0-6.1
fixed
suse enterprise sap 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise sap 15 SP7
1.64.0-150700.1.5
fixed
suse enterprise server 15 SP1
1.40.0-3.6.3
fixed
suse enterprise server 15 SP2
1.40.0-1.15
fixed
suse enterprise server 15 SP3
1.40.0-3.5.1
fixed
suse enterprise server 15 SP4
1.40.0-6.1
fixed
suse enterprise server 15 SP5
1.40.0-6.1
fixed
suse enterprise server 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise server 15 SP7
1.64.0-150700.1.5
fixed
libnghttp2_asio-devel
suse enterprise desktop 15 SP1
1.40.0-3.6.3
fixed
suse enterprise desktop 15 SP2
1.40.0-1.15
fixed
suse enterprise desktop 15 SP3
1.40.0-3.5.1
fixed
suse enterprise desktop 15 SP4
1.40.0-6.1
fixed
suse enterprise desktop 15 SP5
1.40.0-6.1
fixed
suse enterprise desktop 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise desktop 15 SP7
1.40.0-150600.23.2
fixed
suse enterprise sap 15 SP1
1.40.0-3.6.3
fixed
suse enterprise sap 15 SP2
1.40.0-1.15
fixed
suse enterprise sap 15 SP3
1.40.0-3.5.1
fixed
suse enterprise sap 15 SP4
1.40.0-6.1
fixed
suse enterprise sap 15 SP5
1.40.0-6.1
fixed
suse enterprise sap 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise sap 15 SP7
1.40.0-150600.23.2
fixed
suse enterprise server 15 SP1
1.40.0-3.6.3
fixed
suse enterprise server 15 SP2
1.40.0-1.15
fixed
suse enterprise server 15 SP3
1.40.0-3.5.1
fixed
suse enterprise server 15 SP4
1.40.0-6.1
fixed
suse enterprise server 15 SP5
1.40.0-6.1
fixed
suse enterprise server 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise server 15 SP7
1.40.0-150600.23.2
fixed
libnghttp2_asio1
suse enterprise desktop 15 SP1
1.40.0-3.6.3
fixed
suse enterprise desktop 15 SP2
1.40.0-1.15
fixed
suse enterprise desktop 15 SP3
1.40.0-3.5.1
fixed
suse enterprise desktop 15 SP4
1.40.0-6.1
fixed
suse enterprise desktop 15 SP5
1.40.0-6.1
fixed
suse enterprise desktop 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise desktop 15 SP7
1.40.0-150600.23.2
fixed
suse enterprise sap 15 SP1
1.40.0-3.6.3
fixed
suse enterprise sap 15 SP2
1.40.0-1.15
fixed
suse enterprise sap 15 SP3
1.40.0-3.5.1
fixed
suse enterprise sap 15 SP4
1.40.0-6.1
fixed
suse enterprise sap 15 SP5
1.40.0-6.1
fixed
suse enterprise sap 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise sap 15 SP7
1.40.0-150600.23.2
fixed
suse enterprise server 15 SP1
1.40.0-3.6.3
fixed
suse enterprise server 15 SP2
1.40.0-1.15
fixed
suse enterprise server 15 SP3
1.40.0-3.5.1
fixed
suse enterprise server 15 SP4
1.40.0-6.1
fixed
suse enterprise server 15 SP5
1.40.0-6.1
fixed
suse enterprise server 15 SP6
1.40.0-150600.23.2
fixed
suse enterprise server 15 SP7
1.40.0-150600.23.2
fixed