PoC-in-GitHub/2021/CVE-2021-21378.json
2022-12-29 09:19:31 +09:00

31 lines
No EOL
1.3 KiB
JSON

[
{
"id": 583151319,
"name": "CVE-2021-21378",
"full_name": "Live-Hack-CVE\/CVE-2021-21378",
"owner": {
"login": "Live-Hack-CVE",
"id": 121191732,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/121191732?v=4",
"html_url": "https:\/\/github.com\/Live-Hack-CVE"
},
"html_url": "https:\/\/github.com\/Live-Hack-CVE\/CVE-2021-21378",
"description": "Envoy is a cloud-native high-performance edge\/middle\/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the `allow_missing` requirement under `requires_any` due t CVE project by @Sn0wAlice",
"fork": false,
"created_at": "2022-12-28T23:22:55Z",
"updated_at": "2022-12-28T23:22:55Z",
"pushed_at": "2022-12-28T23:22:57Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0
}
]