Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-32976

Опубликовано: 04 июн. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

A flaw was found in Envoy's Brotli decompressor. This flaw allows a remote, unauthenticated attacker to trigger an infinite loop, causing a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2servicemesh-proxyWill not fix
Red Hat OpenShift Service Mesh 2.4 for RHEL 8openshift-service-mesh/grafana-rhel8FixedRHSA-2024:772407.10.2024
Red Hat OpenShift Service Mesh 2.4 for RHEL 8openshift-service-mesh/istio-cni-rhel8FixedRHSA-2024:772407.10.2024
Red Hat OpenShift Service Mesh 2.4 for RHEL 8openshift-service-mesh/istio-must-gather-rhel8FixedRHSA-2024:772407.10.2024
Red Hat OpenShift Service Mesh 2.4 for RHEL 8openshift-service-mesh/kiali-rhel8FixedRHSA-2024:772407.10.2024
Red Hat OpenShift Service Mesh 2.4 for RHEL 8openshift-service-mesh/pilot-rhel8FixedRHSA-2024:772407.10.2024
Red Hat OpenShift Service Mesh 2.4 for RHEL 8openshift-service-mesh/proxyv2-rhel8FixedRHSA-2024:772407.10.2024
Red Hat OpenShift Service Mesh 2.4 for RHEL 8openshift-service-mesh/ratelimit-rhel8FixedRHSA-2024:772407.10.2024
Red Hat OpenShift Service Mesh 2.5 for RHEL 8openshift-service-mesh/grafana-rhel8FixedRHSA-2024:772507.10.2024
Red Hat OpenShift Service Mesh 2.5 for RHEL 8openshift-service-mesh/istio-cni-rhel8FixedRHSA-2024:772507.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2283145envoy: Brotli decompressor infinite loop

EPSS

Процентиль: 8%
0.00028
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

CVSS3: 7.5
debian
больше 1 года назад

Envoy is a cloud-native, open source edge and service proxy. Envoyprox ...

EPSS

Процентиль: 8%
0.00028
Низкий

7.5 High

CVSS3