Логотип exploitDog
bind: "CVE-2024-23325"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-23325"

Количество 5

Количество 5

redhat логотип

CVE-2024-23325

больше 1 года назад

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6 address. It is valid for a client to present its IPv6 address to a target server even though the whole chain is connected via IPv4. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-23325

больше 1 года назад

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6 address. It is valid for a client to present its IPv6 address to a target server even though the whole chain is connected via IPv4. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-23325

больше 1 года назад

Envoy is a high-performance edge/middle/service proxy. Envoy crashes i ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-02906

больше 1 года назад

Уязвимость прокси-сервера Envoy, связанная с не перехваченным исключением, позволяющая нарушителю вызвать аварийное завершение работы приложения

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240423-06

около 1 года назад

Множественные уязвимости consul

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-23325

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6 address. It is valid for a client to present its IPv6 address to a target server even though the whole chain is connected via IPv4. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-23325

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6 address. It is valid for a client to present its IPv6 address to a target server even though the whole chain is connected via IPv4. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-23325

Envoy is a high-performance edge/middle/service proxy. Envoy crashes i ...

CVSS3: 7.5
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-02906

Уязвимость прокси-сервера Envoy, связанная с не перехваченным исключением, позволяющая нарушителю вызвать аварийное завершение работы приложения

CVSS3: 7.5
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240423-06

Множественные уязвимости consul

CVSS3: 7.5
около 1 года назад

Уязвимостей на страницу