Envoy Admin Interface Exposed

medium Web App Scanning Plugin ID 114570

Synopsis

Envoy Admin Interface Exposed

Description

The Envoy Admin interface is an optional Envoy component that lets you view configuration and statistics, modify server behavior and filter traffic according to specific filter rules.

But this unauthenticated interface can expose private information about the running service, allows modification of runtime settings and can also be used to shut the server down.

Solution

Restrict access to the Envoy Admin interface or remove it.

See Also

https://www.envoyproxy.io/docs/envoy/latest/start/quick-start/admin

Plugin Details

Severity: Medium

ID: 114570

Type: remote

Published: 1/28/2025

Updated: 1/28/2025

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 2.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information