Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8659

Опубликовано: 03 мар. 2020
Источник: redhat
CVSS3: 7.5

Описание

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.

A resource consumption vulnerability was found in the servicemesh-proxy in Envoy. An attacker could send specially crafted small HTTP/1.1 packets that, when processed, could cause excessive amounts of memory to be used, possibly degrading or crashing the application.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1802539envoy: Excessive CPU and/or memory usage when proxying HTTP/1.1

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 6 лет назад

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.

CVSS3: 7.5
debian
почти 6 лет назад

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when ...

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость сетевого программного средства Envoy, связанная с неконтролируемым расходом ресурса, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3