Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-53271

Опубликовано: 18 дек. 2024
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.

A flaw was found in Envoy. In affected versions, Envoy does not properly handle certain HTTP 1.1 responses. Specially-crafted requests may trigger failures or application crashes in networked devices, leading to a denial of service.

Отчет

This vulnerability is rated Important due to Envoy's improper handling of HTTP 1.1 non-101 1xx responses, potentially leading to downstream failures in networked devices, this issue can disrupt service communication, requiring prompt attention and resolution to maintain network stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/pilot-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-670
https://bugzilla.redhat.com/show_bug.cgi?id=2333078envoy: HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy

EPSS

Процентиль: 47%
0.00622
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
больше 1 года назад

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 7.1
debian
больше 1 года назад

Envoy is a cloud-native high-performance edge/middle/service proxy. In ...

CVSS3: 7.1
fstec
почти 2 года назад

Уязвимость конфигурации envoy.reloadable_features.http1_balsa_delay_reset прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 47%
0.00622
Низкий

7.1 High

CVSS3