Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29228

Опубликовано: 09 июн. 2022
Источник: redhat
CVSS3: 7.5

Описание

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on earlier versions. continueDecoding() shouldn’t ever be called from filters after a local reply has been sent. Users are advised to upgrade. There are no known workarounds for this issue.

A flaw was found in Envoy. The OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on earlier versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0servicemesh-proxyAffected
OpenShift Service Mesh 2.1servicemesh-proxyFixedRHSA-2022:500413.06.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2088740envoy: oauth filter calls continueDecoding() from within decodeHeaders()

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on earlier versions. continueDecoding() shouldn’t ever be called from filters after a local reply has been sent. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 7.5
debian
около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

oracle-oval
около 3 лет назад

ELSA-2022-9589: olcne security update (IMPORTANT)

oracle-oval
около 3 лет назад

ELSA-2022-9588: olcne security update (IMPORTANT)

oracle-oval
около 3 лет назад

ELSA-2022-9587: olcne security update (IMPORTANT)

7.5 High

CVSS3