Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in Envoy Gateway that could allow unauthorized access to sensitive files on the gateway controller pod, such as service account tokens or TLS certificates. This could potentially expose credentials, granting access to Kubernetes API Server or Gateway xDS server information.
- Allows reading sensitive files from gateway systems.
- Matters due to potential credential exposure.
- Confirm relevance and exposure of Envoy Gateway.
Attack Path
How an attacker could exploit the issue
An attacker with limited access could exploit this vulnerability by submitting specially crafted Lua code through an EnvoyExtensionPolicy. The validation process for paths in this code does not correctly handle redundant separators, allowing the Lua code to bypass security checks. This bypass enables the attacker to read sensitive files from the gateway controller pod, potentially exposing credentials that could grant access to critical Kubernetes or xDS server information.
- Requires authenticated access.
- Triggered by malformed path in Lua code.
- Allows arbitrary file read of sensitive data.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, submitted Lua code could allow an attacker with low privileges to read arbitrary files from the gateway controller pod. This could expose sensitive information such as Kubernetes service-account tokens, TLS certificates, and process environment data. The disclosed credentials may grant access to the Kubernetes API Server or Gateway xDS server.
- Gateway controller pod files at risk.
- Malicious Lua code bypasses validation.
- Credentials may expose sensitive services.
Operational Fix
Recommended remediation, mitigation, and detection steps
Real-world ownership for this issue likely resides with platform or infrastructure teams managing the Envoy Gateway, with oversight from security teams. The first practical step is to identify all instances of Envoy Gateway, confirm their exposure and business criticality, and then coordinate remediation with the accountable application or service owners.
- Platform/infrastructure teams own the issue.
- Verify Envoy Gateway exposure and criticality.
- Plan targeted remediation actions.