PoC-in-GitHub/2021/CVE-2021-21378.json

31 lines
1.3 KiB
JSON
Raw Normal View History

2022-12-23 03:19:18 +09:00
[
{
2022-12-29 09:19:31 +09:00
"id": 583151319,
"name": "CVE-2021-21378",
"full_name": "Live-Hack-CVE\/CVE-2021-21378",
2022-12-23 03:19:18 +09:00
"owner": {
"login": "Live-Hack-CVE",
"id": 121191732,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/121191732?v=4",
"html_url": "https:\/\/github.com\/Live-Hack-CVE"
},
2022-12-29 09:19:31 +09:00
"html_url": "https:\/\/github.com\/Live-Hack-CVE\/CVE-2021-21378",
"description": "Envoy is a cloud-native high-performance edge\/middle\/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the `allow_missing` requirement under `requires_any` due t CVE project by @Sn0wAlice",
2022-12-23 03:19:18 +09:00
"fork": false,
2022-12-29 09:19:31 +09:00
"created_at": "2022-12-28T23:22:55Z",
"updated_at": "2022-12-28T23:22:55Z",
"pushed_at": "2022-12-28T23:22:57Z",
2022-12-23 03:19:18 +09:00
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0
}
]