In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improper Output Neutralization for Logs vulnerabilities in an interactive lesson.
Start learningThere is no fixed version for envoyproxy/envoy
.
Affected versions of this package are vulnerable to Improper Output Neutralization for Logs due to improper sanitization of HTTP headers, particularly the x-forwarded-for
header. An attacker can manipulate log entries or execute reflected cross-site scripting attacks by injecting malicious payloads into service mesh logs.