Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29227

Опубликовано: 09 июн. 2022
Источник: redhat
CVSS3: 7.5

Описание

Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers, there’s a lifetime bug which can be triggered. If while replaying the request Envoy sends a local reply when the redirect headers are processed, the downstream state indicates that the downstream stream is not complete. On sending the local reply, Envoy will attempt to reset the upstream stream, but as it is actually complete, and deleted, this result in a use-after-free. Users are advised to upgrade. Users unable to upgrade are advised to disable internal redirects if crashes are observed.

A flaw was found in Envoy. Internal redirects for requests with bodies or trailers are not safe if the redirect prompts an Envoy-generated local reply. A remote attacker can exploit this to cause a denial of service.

Меры по смягчению последствий

Disable internal redirects if crashes are observed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0servicemesh-proxyAffected
OpenShift Service Mesh 2.1servicemesh-proxyAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2088741envoy: Internal redirect crash for requests with body/trailers

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers, there’s a lifetime bug which can be triggered. If while replaying the request Envoy sends a local reply when the redirect headers are processed, the downstream state indicates that the downstream stream is not complete. On sending the local reply, Envoy will attempt to reset the upstream stream, but as it is actually complete, and deleted, this result in a use-after-free. Users are advised to upgrade. Users unable to upgrade are advised to disable internal redirects if crashes are observed.

CVSS3: 7.5
debian
около 3 лет назад

Envoy is a cloud-native high-performance edge/middle/service proxy. In ...

oracle-oval
около 3 лет назад

ELSA-2022-9589: olcne security update (IMPORTANT)

oracle-oval
около 3 лет назад

ELSA-2022-9588: olcne security update (IMPORTANT)

oracle-oval
около 3 лет назад

ELSA-2022-9587: olcne security update (IMPORTANT)

7.5 High

CVSS3