Логотип exploitDog
bind:CVE-2021-32781
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-32781

Количество 6

Количество 6

redhat логотип

CVE-2021-32781

почти 4 года назад

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be stopped completely and result in accessing a freed memory block. A specifically constructed request delivered by an untrusted downstream or upstream peer in the presence of extensions that modify and increase the size of request or response bodies resulting in a Denial of Service when using extensions that modify and increase the size of request or response bodies, such as decompressor filter. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to address incomplete termination of request processing after locally generated response. As a workaround disable Envoy's decompressor, json...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-32781

почти 4 года назад

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be stopped completely and result in accessing a freed memory block. A specifically constructed request delivered by an untrusted downstream or upstream peer in the presence of extensions that modify and increase the size of request or response bodies resulting in a Denial of Service when using extensions that modify and increase the size of request or response bodies, such as decompressor filter. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to address incomplete termination of request processing after locally generated response. As a workaround disable Envoy's decompressor, json-tr

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2021-32781

почти 4 года назад

Envoy is an open source L7 proxy and communication bus designed for la ...

CVSS3: 8.6
EPSS: Низкий
oracle-oval логотип

ELSA-2021-9525

больше 3 лет назад

ELSA-2021-9525: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-9546

больше 3 лет назад

ELSA-2021-9546: olcne istio istio kubernetes security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-9526

больше 3 лет назад

ELSA-2021-9526: olcne security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-32781

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be stopped completely and result in accessing a freed memory block. A specifically constructed request delivered by an untrusted downstream or upstream peer in the presence of extensions that modify and increase the size of request or response bodies resulting in a Denial of Service when using extensions that modify and increase the size of request or response bodies, such as decompressor filter. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to address incomplete termination of request processing after locally generated response. As a workaround disable Envoy's decompressor, json...

CVSS3: 7.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-32781

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be stopped completely and result in accessing a freed memory block. A specifically constructed request delivered by an untrusted downstream or upstream peer in the presence of extensions that modify and increase the size of request or response bodies resulting in a Denial of Service when using extensions that modify and increase the size of request or response bodies, such as decompressor filter. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to address incomplete termination of request processing after locally generated response. As a workaround disable Envoy's decompressor, json-tr

CVSS3: 8.6
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-32781

Envoy is an open source L7 proxy and communication bus designed for la ...

CVSS3: 8.6
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2021-9525

ELSA-2021-9525: olcne security update (IMPORTANT)

больше 3 лет назад
oracle-oval логотип
ELSA-2021-9546

ELSA-2021-9546: olcne istio istio kubernetes security update (IMPORTANT)

больше 3 лет назад
oracle-oval логотип
ELSA-2021-9526

ELSA-2021-9526: olcne security update (IMPORTANT)

больше 3 лет назад

Уязвимостей на страницу