Envoy是一款开源的分布式代理服务器。 Envoy 存在信任管理问题漏洞,该漏洞源于Envoy 不会将它从对等方(作为 TLS 客户端或 TLS 服务器)接受的证书集限制为仅包含必要的扩展密钥使用(id-kp-serverAuth 和 id-kp-clientAuth,分别为 )。 这意味着对等点可以提供电子邮件证书(例如 id-kp-emailProtection),作为叶证书或链中的 CA,并且将被 TLS 接受。 当与拉取请求 #630 中描述的问题结合使用时,这尤其糟糕,因为它允许仅用于 S/M
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | envoy | >= 1.20.0, < 1.20.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-43826 | 7.5 HIGH | Crash when tunneling TCP over HTTP in Envoy |
| CVE-2022-21655 | 7.5 HIGH | Incorrect handling of internal redirects results in crash in Envoy |
| CVE-2021-43824 | 7.5 HIGH | Null pointer dereference in envoy |
| CVE-2022-21654 | 7.4 HIGH | Incorrect configuration handling allows TLS session re-use without re-validation in Envoy |
| CVE-2022-21656 | 7.4 HIGH | X.509 subjectAltName matching bypass in Envoy |
| CVE-2021-43825 | 6.1 MEDIUM | Use-after-free in Envoy |
| CVE-2022-23606 | 4.4 MEDIUM | Crash when a cluster is deleted in Envoy |
No comments yet