CVE-2021-32779
HIGHDescription
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' element as part of the path element. Envoy is configured with an RBAC filter for authorization or similar mechanism with an explicit case of a final "/admin" path element, or is using a negative assertion with final path element of "/admin". The client sends request to "/app1/admin#foo". In Envoy prior to 1.18.0, or 1.18.0+ configured with path_normalization=false. Envoy treats fragment as a suffix of the query string when present, or as a suffix of the path when query string is absent, so it evaluates the final path element as "/admin#foo" and mismatches with the configured "/admin" path element. In Envoy 1.18.0+ configured with path_normalization=true. Envoy transforms this to /app1/admin%23foo and mismatches with the configured /admin prefix. The resulting URI is sent to the next server-agent with the offending "#foo" fragment which violates RFC3986 or with the nonsensical "%23foo" text appended. A specifically constructed request with URI containing '#fragment' element delivered by an untrusted client in the presence of path based request authorization resulting in escalation of Privileges when path based request authorization extensions. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes that removes fragment from URI path in incoming requests.
How to fix
TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploit Intelligence
Moderate risk: more likely to be exploited than 58% of all known CVEs.
References
Related Vulnerabilities
Other CWE-551 vulnerabilities, ordered by exploit likelihood. View all
| CVE | Severity | CVSS | EPSS | Exploited | Fix |
|---|---|---|---|---|---|
| CVE-2021-34429 | Medium | 5.3 | 99% | - | Fix |
| CVE-2021-28164 | Medium | 5.3 | 82% | - | Fix |
| CVE-2021-28165 | High | 7.5 | 54% | - | Fix |
| CVE-2023-23924 | Critical | 10.0 | 3.6% | - | - |
| CVE-2021-32777 | High | 8.6 | 3.3% | - | Fix |
| CVE-2026-44575 | High | 7.5 | 1.6% | - | Fix |
Common questions
How do I fix CVE-2021-32779?
Upgrade envoy to 1.18.4 or later.
Is CVE-2021-32779 being actively exploited?
Not that we know of. CVE-2021-32779 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 0.95% is the estimated probability that it will be exploited in the next 30 days. That is higher than 58% of all scored CVEs.
How severe is CVE-2021-32779?
CVE-2021-32779 has a CVSS v3 base score of 8.6, rated high. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.
What does CVE-2021-32779 affect?
Published advisories record a fix for envoy (NVD). Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.
Embed a live status badge for CVE-2021-32779
Markdown
[](https://tridentstack.com/cve/CVE-2021-32779)HTML
<a href="https://tridentstack.com/cve/CVE-2021-32779"><img src="https://tridentstack.com/cve/badge/CVE-2021-32779.svg" alt="CVE-2021-32779"></a>Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.