Количество 10
Количество 10

CVE-2023-27493
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy does not sanitize or escape request properties when generating request headers. This can lead to characters that are illegal in header values to be sent to the upstream service. In the worst case, it can cause upstream service to interpret the original request as two pipelined requests, possibly bypassing the intent of Envoy’s security policy. Versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9 contain a patch. As a workaround, disable adding request headers based on the downstream request properties, such as downstream certificate properties.

CVE-2023-27493
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy does not sanitize or escape request properties when generating request headers. This can lead to characters that are illegal in header values to be sent to the upstream service. In the worst case, it can cause upstream service to interpret the original request as two pipelined requests, possibly bypassing the intent of Envoy’s security policy. Versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9 contain a patch. As a workaround, disable adding request headers based on the downstream request properties, such as downstream certificate properties.
CVE-2023-27493
Envoy is an open source edge and service proxy designed for cloud-nati ...

BDU:2023-02000
Уязвимость реализации протокола mTLS (mutual TLS) прокси-сервера Envoy, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)
ELSA-2023-23649
ELSA-2023-23649: olcne security update (IMPORTANT)
ELSA-2023-23648
ELSA-2023-23648: olcne security update (IMPORTANT)
ELSA-2023-12357
ELSA-2023-12357: istio security update (IMPORTANT)
ELSA-2023-12356
ELSA-2023-12356: istio security update (IMPORTANT)
ELSA-2023-12355
ELSA-2023-12355: istio security update (IMPORTANT)
ELSA-2023-12354
ELSA-2023-12354: istio security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2023-27493 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy does not sanitize or escape request properties when generating request headers. This can lead to characters that are illegal in header values to be sent to the upstream service. In the worst case, it can cause upstream service to interpret the original request as two pipelined requests, possibly bypassing the intent of Envoy’s security policy. Versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9 contain a patch. As a workaround, disable adding request headers based on the downstream request properties, such as downstream certificate properties. | CVSS3: 8.1 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2023-27493 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy does not sanitize or escape request properties when generating request headers. This can lead to characters that are illegal in header values to be sent to the upstream service. In the worst case, it can cause upstream service to interpret the original request as two pipelined requests, possibly bypassing the intent of Envoy’s security policy. Versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9 contain a patch. As a workaround, disable adding request headers based on the downstream request properties, such as downstream certificate properties. | CVSS3: 8.1 | 0% Низкий | больше 2 лет назад |
CVE-2023-27493 Envoy is an open source edge and service proxy designed for cloud-nati ... | CVSS3: 8.1 | 0% Низкий | больше 2 лет назад | |
![]() | BDU:2023-02000 Уязвимость реализации протокола mTLS (mutual TLS) прокси-сервера Envoy, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling) | CVSS3: 8.1 | 0% Низкий | больше 2 лет назад |
ELSA-2023-23649 ELSA-2023-23649: olcne security update (IMPORTANT) | больше 2 лет назад | |||
ELSA-2023-23648 ELSA-2023-23648: olcne security update (IMPORTANT) | больше 2 лет назад | |||
ELSA-2023-12357 ELSA-2023-12357: istio security update (IMPORTANT) | больше 2 лет назад | |||
ELSA-2023-12356 ELSA-2023-12356: istio security update (IMPORTANT) | больше 2 лет назад | |||
ELSA-2023-12355 ELSA-2023-12355: istio security update (IMPORTANT) | больше 2 лет назад | |||
ELSA-2023-12354 ELSA-2023-12354: istio security update (IMPORTANT) | больше 2 лет назад |
Уязвимостей на страницу