Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-53271

Опубликовано: 18 дек. 2024
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
Версия от 1.31.0 (включая) до 1.31.5 (исключая)
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
Версия от 1.32.0 (включая) до 1.32.3 (включая)

EPSS

Процентиль: 0%
0.00005
Низкий

7.1 High

CVSS3

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 7.1
redhat
около 1 года назад

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 7.1
debian
около 1 года назад

Envoy is a cloud-native high-performance edge/middle/service proxy. In ...

CVSS3: 7.1
fstec
около 1 года назад

Уязвимость конфигурации envoy.reloadable_features.http1_balsa_delay_reset прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 0%
0.00005
Низкий

7.1 High

CVSS3

Дефекты

CWE-670