Количество 11
Количество 11
GHSA-xwx5-5c9g-x68x
Ill-formed headers may lead to unexpected behavior in Istio

CVE-2022-31045
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and 1.14.1. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-31045
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and 1.14.1. Users are advised to upgrade. There are no known workarounds for this issue.
ELSA-2022-9774
ELSA-2022-9774: istio security update (IMPORTANT)
ELSA-2022-9773
ELSA-2022-9773: istio security update (IMPORTANT)
ELSA-2022-9772
ELSA-2022-9772: istio security update (IMPORTANT)
ELSA-2022-9771
ELSA-2022-9771: istio security update (IMPORTANT)
ELSA-2022-9589
ELSA-2022-9589: olcne security update (IMPORTANT)
ELSA-2022-9588
ELSA-2022-9588: olcne security update (IMPORTANT)
ELSA-2022-9587
ELSA-2022-9587: olcne security update (IMPORTANT)
ELSA-2022-9586
ELSA-2022-9586: olcne security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-xwx5-5c9g-x68x Ill-formed headers may lead to unexpected behavior in Istio | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2022-31045 Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and 1.14.1. Users are advised to upgrade. There are no known workarounds for this issue. | CVSS3: 9.8 | 0% Низкий | около 3 лет назад |
![]() | CVE-2022-31045 Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and 1.14.1. Users are advised to upgrade. There are no known workarounds for this issue. | CVSS3: 7 | 0% Низкий | около 3 лет назад |
ELSA-2022-9774 ELSA-2022-9774: istio security update (IMPORTANT) | почти 3 года назад | |||
ELSA-2022-9773 ELSA-2022-9773: istio security update (IMPORTANT) | почти 3 года назад | |||
ELSA-2022-9772 ELSA-2022-9772: istio security update (IMPORTANT) | почти 3 года назад | |||
ELSA-2022-9771 ELSA-2022-9771: istio security update (IMPORTANT) | почти 3 года назад | |||
ELSA-2022-9589 ELSA-2022-9589: olcne security update (IMPORTANT) | около 3 лет назад | |||
ELSA-2022-9588 ELSA-2022-9588: olcne security update (IMPORTANT) | около 3 лет назад | |||
ELSA-2022-9587 ELSA-2022-9587: olcne security update (IMPORTANT) | около 3 лет назад | |||
ELSA-2022-9586 ELSA-2022-9586: olcne security update (IMPORTANT) | около 3 лет назад |
Уязвимостей на страницу