{"id":"CVE-2021-29492","details":"Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`. A backend server could then decode slash sequences and normalize path and provide an attacker access beyond the scope provided for by the access control policy. ### Impact Escalation of Privileges when using RBAC or JWT filters with enforcement based on URL path. Users with back end servers that interpret `%2F` and `/` and `%5C` and `\\` interchangeably are impacted. ### Attack Vector URL paths containing escaped slash characters delivered by untrusted client. Patches in versions 1.18.3, 1.17.3, 1.16.4, 1.15.5 contain new path normalization option to decode escaped slash characters. As a workaround, if back end servers treat `%2F` and `/` and `%5C` and `\\` interchangeably and a URL path based access control is configured, one may reconfigure the back end server to not treat `%2F` and `/` and `%5C` and `\\` interchangeably.","aliases":["BIT-envoy-2021-29492","GHSA-4987-27fx-x6cf"],"modified":"2026-08-07T15:13:55.325095Z","published":"2021-05-28T21:15:08.670Z","references":[{"type":"ADVISORY","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-4987-27fx-x6cf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/envoyproxy/envoy","events":[{"introduced":"0"},{"fixed":"623479e875619a71adc2ad0ea3cfc9f67a79e765"},{"introduced":"8fb3cb86082b17144a80402f5367ae65f06083bd"},{"fixed":"bf5d0eb44b781ac26ff1513700bcb114b7cf4300"},{"introduced":"5c801b25cae04f06bf48248c90e87d623d7a6283"},{"fixed":"46bf743b97d0d3f01ff437b2f10cc0bd9cdfe6e4"},{"introduced":"345ffe37148b7a35b6e8e04db0300463689e3ff1"},{"fixed":"98c1c9e9a40804b93b074badad1cdf284b47d58b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.15.5"},{"introduced":"1.16.0"},{"fixed":"1.16.4"},{"introduced":"1.17.0"},{"fixed":"1.17.3"},{"introduced":"1.18.0"},{"fixed":"1.18.3"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*"}}],"versions":["v1.15.4","v1.17.2","v1.18.2","v1.16.3","v1.18.1","v1.18.0","v1.17.1","v1.17.0","v1.15.3","v1.16.2","v1.16.1","v1.16.0","v1.15.2","v1.15.1","v1.15.0","v1.14.0","v1.13.0","v1.12.0","v1.11.0","v1.10.0","v1.9.0","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29492.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}]}