Логотип exploitDog
bind: "CVE-2024-27919"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-27919"

Количество 5

Количество 5

redhat логотип

CVE-2024-27919

около 1 года назад

Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an attacker to send an sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption. This can lead to denial of service through memory exhaustion. Users should upgrade to versions 1.29.2 to mitigate the effects of the CONTINUATION flood. Note that this vulnerability is a regression in Envoy version 1.29.0 and 1.29.1 only. As a workaround, downgrade to version 1.28.1 or earlier or disable HTTP/2 protocol for downstream connections.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2024-27919

около 1 года назад

Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an attacker to send an sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption. This can lead to denial of service through memory exhaustion. Users should upgrade to versions 1.29.2 to mitigate the effects of the CONTINUATION flood. Note that this vulnerability is a regression in Envoy version 1.29.0 and 1.29.1 only. As a workaround, downgrade to version 1.28.1 or earlier or disable HTTP/2 protocol for downstream connections.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2024-27919

около 1 года назад

Envoy is a cloud-native, open-source edge and service proxy. In versio ...

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2024-02719

больше 1 года назад

Уязвимость oghttp-кодека прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Средний
redos логотип

ROS-20240805-07

11 месяцев назад

Уязвимость consul

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-27919

Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an attacker to send an sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption. This can lead to denial of service through memory exhaustion. Users should upgrade to versions 1.29.2 to mitigate the effects of the CONTINUATION flood. Note that this vulnerability is a regression in Envoy version 1.29.0 and 1.29.1 only. As a workaround, downgrade to version 1.28.1 or earlier or disable HTTP/2 protocol for downstream connections.

CVSS3: 7.5
49%
Средний
около 1 года назад
nvd логотип
CVE-2024-27919

Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an attacker to send an sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption. This can lead to denial of service through memory exhaustion. Users should upgrade to versions 1.29.2 to mitigate the effects of the CONTINUATION flood. Note that this vulnerability is a regression in Envoy version 1.29.0 and 1.29.1 only. As a workaround, downgrade to version 1.28.1 or earlier or disable HTTP/2 protocol for downstream connections.

CVSS3: 7.5
49%
Средний
около 1 года назад
debian логотип
CVE-2024-27919

Envoy is a cloud-native, open-source edge and service proxy. In versio ...

CVSS3: 7.5
49%
Средний
около 1 года назад
fstec логотип
BDU:2024-02719

Уязвимость oghttp-кодека прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
49%
Средний
больше 1 года назад
redos логотип
ROS-20240805-07

Уязвимость consul

CVSS3: 7.5
49%
Средний
11 месяцев назад

Уязвимостей на страницу