Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wjf-62hw-q78r

Опубликовано: 10 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Excessive CPU usage

Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset.

Impact

This can result in a DoS condition.

Patches

Pomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched.

Workarounds

N/A

References

envoy GSA envoy CVE envoy announcement

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

github.com/pomerium/pomerium

go
Затронутые версииВерсия исправления

< 0.14.8

0.14.8

Наименование

github.com/pomerium/pomerium

go
Затронутые версииВерсия исправления

= 0.15.0

0.15.1

EPSS

Процентиль: 61%
0.00407
Низкий

7.5 High

CVSS3

Дефекты

CWE-834

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This can result in a DoS condition. Pomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched.

EPSS

Процентиль: 61%
0.00407
Низкий

7.5 High

CVSS3

Дефекты

CWE-834