Database/Container, Kubernetes & orchestration
Envoy: Client can forge the x-envoy-original-path header and bypass JWT checks
CVE-2023-27487Container, Kubernetes & orchestrationcurated
Impact
Client can forge the x-envoy-original-path header and bypass JWT checks
Who can reach it
Unauthenticated network
What to do
Upgrade Envoy; strip x-envoy headers at the edge
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.