Количество 8
Количество 8

CVE-2022-29225
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.

CVE-2022-29225
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.
CVE-2022-29225
Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

BDU:2022-04157
Уязвимость компонента decode/encodeBody прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании
ELSA-2022-9589
ELSA-2022-9589: olcne security update (IMPORTANT)
ELSA-2022-9588
ELSA-2022-9588: olcne security update (IMPORTANT)
ELSA-2022-9587
ELSA-2022-9587: olcne security update (IMPORTANT)
ELSA-2022-9586
ELSA-2022-9586: olcne security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2022-29225 Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад |
![]() | CVE-2022-29225 Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад |
CVE-2022-29225 Envoy is a cloud-native high-performance proxy. In versions prior to 1 ... | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
![]() | BDU:2022-04157 Уязвимость компонента decode/encodeBody прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | около 3 лет назад |
ELSA-2022-9589 ELSA-2022-9589: olcne security update (IMPORTANT) | около 3 лет назад | |||
ELSA-2022-9588 ELSA-2022-9588: olcne security update (IMPORTANT) | около 3 лет назад | |||
ELSA-2022-9587 ELSA-2022-9587: olcne security update (IMPORTANT) | около 3 лет назад | |||
ELSA-2022-9586 ELSA-2022-9586: olcne security update (IMPORTANT) | около 3 лет назад |
Уязвимостей на страницу