blob: 207c10f24769687d47bdfec5b95397472127e209 [file] [log] [blame]
id: GO-2025-3504
modules:
- module: github.com/envoyproxy/gateway
versions:
- fixed: 1.2.7
- introduced: 1.3.0-rc.1
- fixed: 1.3.1
vulnerable_at: 1.3.0
summary: Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway
cves:
- CVE-2025-25294
ghsas:
- GHSA-mf24-chxh-hmvj
references:
- advisory: https://github.com/envoyproxy/gateway/security/advisories/GHSA-mf24-chxh-hmvj
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-25294
- fix: https://github.com/envoyproxy/gateway/commit/041d474a70d5921e5d65e6e14ea60e14dac70b01
- fix: https://github.com/envoyproxy/gateway/commit/358bed50dcb7b32f39a2edb252fb1399c7fc65dc
- fix: https://github.com/envoyproxy/gateway/commit/8f48f5199cf1bbb9a8ac0695c5171bfef6c9198a
- web: https://github.com/envoyproxy/gateway/releases/tag/v1.2.7
- web: https://github.com/envoyproxy/gateway/releases/tag/v1.3.1
source:
id: GHSA-mf24-chxh-hmvj
created: 2025-03-10T14:13:13.515665-04:00
review_status: UNREVIEWED