Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Envoy 缓冲区错误漏洞
Vulnerability Description
Envoy是一款开源的分布式代理服务器。 Envoy 1.12.0版本中存在缓冲区错误漏洞。攻击者可利用该漏洞绕过路由匹配并在系统上提升权限或获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A