Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-53269

Опубликовано: 18 дек. 2024
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Users are advised to upgrade. Users unable to upgrade may disable Happy Eyeballs and/or change the IP configuration.

A flaw was found in Envoy. If the cluster configuration file contains malformed IP addresses, the Happy Eyeballs sorting algorithm may fail and trigger an application crash, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/pilot-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-670
https://bugzilla.redhat.com/show_bug.cgi?id=2333088envoy: Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoy

EPSS

Процентиль: 0%
0.00005
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
nvd
около 1 года назад

Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Users are advised to upgrade. Users unable to upgrade may disable Happy Eyeballs and/or change the IP configuration.

CVSS3: 4.5
debian
около 1 года назад

Envoy is a cloud-native high-performance edge/middle/service proxy. Wh ...

CVSS3: 4.5
fstec
около 1 года назад

Уязвимость алгоритма сортировки Happy Eyeballs прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 0%
0.00005
Низкий

4.5 Medium

CVSS3