Envoy是一款开源的分布式代理服务器。 Envoy存在安全漏洞,该漏洞源于如果序列化不完整的UTF-8字符串,可能会从下游数据中抛出未捕获的异常,未捕获的异常会导致崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | envoy | >= 1.30.0, <= 11.30.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-32976 | 7.5 HIGH | Envoy can enter an endless loop while decompressing Brotli data with extra input |
| CVE-2024-23326 | 5.9 MEDIUM | Envoy incorrectly accepts HTTP 200 response for entering upgrade mode |
| CVE-2024-32974 | 5.9 MEDIUM | Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete() |
| CVE-2024-32975 | 5.9 MEDIUM | Envoy crashes in QuicheDataReader::PeekVarInt62Length() |
| CVE-2024-34362 | 5.9 MEDIUM | Envoy affected by a crash (use-after-free) in EnvoyQuicServerStream |
| CVE-2024-34364 | 5.7 MEDIUM | Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response |
No comments yet