CVE-2025-0754
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 28, 2025
CWE ID 117
Summary
CVE-2025-0754 is a vulnerability affecting OpenShift Service Mesh versions 2.6.3 and 2.5.6. The issue lies in Envoy's improper sanitization of HTTP headers, specifically the x-forwarded-for header. This security flaw enables attackers to inject malicious payloads into service mesh logs through log injection and spoofing attacks. Consequences of these attacks include manipulation of log entries and potential reflected cross-site scripting (XSS) vulnerabilities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Red Hat