Envoy是一款开源的分布式代理服务器。 Envoy 存在资源管理错误漏洞,该漏洞源于Envoy跟踪缓冲的请求和响应数据的数量,如果缓冲数据的数量超过限制,就发送413或500个响应,从而中止请求。然而当缓冲区溢出时,响应由过滤器链处理,操作可能不会正确中止,并导致访问一个释放的内存块。攻击者可利用该漏洞导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | envoy | < 1.18.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-43826 | 7.5 HIGH | Crash when tunneling TCP over HTTP in Envoy |
| CVE-2022-21655 | 7.5 HIGH | Incorrect handling of internal redirects results in crash in Envoy |
| CVE-2021-43824 | 7.5 HIGH | Null pointer dereference in envoy |
| CVE-2022-21654 | 7.4 HIGH | Incorrect configuration handling allows TLS session re-use without re-validation in Envoy |
| CVE-2022-21656 | 7.4 HIGH | X.509 subjectAltName matching bypass in Envoy |
| CVE-2022-21657 | 6.8 MEDIUM | X.509 Extended Key Usage and Trust Purposes bypass in Envoy |
| CVE-2022-23606 | 4.4 MEDIUM | Crash when a cluster is deleted in Envoy |
No comments yet