Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Breaking caches and bypassing Istio RBAC with HTTP response header injection

Blog post from Snyk

Post Details
Company
Date Published
Author
Rory McNamara
Word Count
2,498
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

"` The attack exploits a vulnerability in caching and bypassing Istio RBAC using HTTP response header injection. The attacker forces NGINX to cache responses, allowing them to target other users with vulnerabilities that are typically only self-exploitable. The second attack bypasses path-based RBAC rules in Kubernetes Istio, enabling full interaction with protected applications without interference from Istio. The vulnerability is exploited by injecting HTTP response headers into the response, causing NGINX to cache the response and provide it to another user. This can be achieved by tricking Envoy, a reverse proxy underpinning Istio, into believing that a connection has been successfully upgraded to a WebSocket connection, allowing data to be forwarded to the upstream application server without additional processing or RBAC validation. The best mitigation is to fully evaluate the applications themselves to ensure they do not contain HTTP response header injection vulnerabilities.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 5 1,303 182 75 -7%
Platform Engineering 1 220 57 37 -27%
Real-time 1 2,587 688 208 +9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.