Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29225

Опубликовано: 09 июн. 2022
Источник: redhat
CVSS3: 7.5

Описание

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.

A flaw was found in Envoy. A specifically constructed HTTP body delivered by an untrusted downstream or upstream peer whose decompressed size is dramatically larger than the compressed size can be sent by an attacker to cause a denial of service.

Меры по смягчению последствий

This can be mitigated by disabling decompression in Envoy.

Дополнительная информация

Статус:

Important
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=2088737envoy: Decompressors can be zip bombed

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.

CVSS3: 7.5
debian
около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость компонента decode/encodeBody прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании

oracle-oval
около 3 лет назад

ELSA-2022-9589: olcne security update (IMPORTANT)

oracle-oval
около 3 лет назад

ELSA-2022-9588: olcne security update (IMPORTANT)

7.5 High

CVSS3