VDB
Sign up
MEDIUM6.5

GHSA-mp85-7mrq-r866

Envoy crashes when JWT authentication is configured with the remote JWKS fetching

Quick fix

GHSA-mp85-7mrq-r866 — github.com/envoyproxy/envoy: upgrade to the fixed version with the command below.

go get github.com/envoyproxy/envoy@v1.36.3

Details

### Summary Envoy crashes when JWT authentication is configured with the remote JWKS fetching, `allow_missing_or_failed` is enabled, multiple JWT tokens are present in the request headers and the JWKS fetch fails.

### Details This is caused by a re-entry bug in the `JwksFetcherImpl`. When the first token's JWKS fetch fails, `onJwksError()` callback triggers processing of the second token, which calls fetch() again on the same fetcher object.

The original callback's reset() then clears the second fetch's state (`receiver_ and request_`) which causes a crash when the async HTTP response arrives.

### PoC * `allow_missing_or_failed` or `allow_missing` is enabled * The client send 2 Authorization headers * the remote JWKS fetching failed * There will be crash

### Impact DoS and Crash

### Mitigation * Disable the `allow_missing_or_failed` or `allow_missing`

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/envoyproxy/envoy
Introduced in: 1.36.0Fixed in: 1.36.3
Fixgo get github.com/envoyproxy/envoy@v1.36.3
Go/github.com/envoyproxy/envoy
Introduced in: 1.35.0Fixed in: 1.35.7
Fixgo get github.com/envoyproxy/envoy@v1.35.7
Go/github.com/envoyproxy/envoy
Introduced in: 1.34.0Fixed in: 1.34.11
Fixgo get github.com/envoyproxy/envoy@v1.34.11
Go/github.com/envoyproxy/envoy
Introduced in: 0Fixed in: 1.33.13
Fixgo get github.com/envoyproxy/envoy@v1.33.13

References