GHSA-mp85-7mrq-r866
Envoy crashes when JWT authentication is configured with the remote JWKS fetching
Quick fix
GHSA-mp85-7mrq-r866 — github.com/envoyproxy/envoy: upgrade to the fixed version with the command below.
go get github.com/envoyproxy/envoy@v1.36.3Details
### Summary Envoy crashes when JWT authentication is configured with the remote JWKS fetching, `allow_missing_or_failed` is enabled, multiple JWT tokens are present in the request headers and the JWKS fetch fails.
### Details This is caused by a re-entry bug in the `JwksFetcherImpl`. When the first token's JWKS fetch fails, `onJwksError()` callback triggers processing of the second token, which calls fetch() again on the same fetcher object.
The original callback's reset() then clears the second fetch's state (`receiver_ and request_`) which causes a crash when the async HTTP response arrives.
### PoC * `allow_missing_or_failed` or `allow_missing` is enabled * The client send 2 Authorization headers * the remote JWKS fetching failed * There will be crash
### Impact DoS and Crash
### Mitigation * Disable the `allow_missing_or_failed` or `allow_missing`
Are you affected?
Enter the version of the package you're using.
Affected packages
1.36.0Fixed in: 1.36.3go get github.com/envoyproxy/envoy@v1.36.31.35.0Fixed in: 1.35.7go get github.com/envoyproxy/envoy@v1.35.71.34.0Fixed in: 1.34.11go get github.com/envoyproxy/envoy@v1.34.110Fixed in: 1.33.13go get github.com/envoyproxy/envoy@v1.33.13