Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the failure of a websocket handshake will trigger a local reply leading to the crash of Envoy. This vulnerability is fixed in 1.33.1, 1.32.4, 1.31.6, and 1.30.10.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HEnvoyproxy Envoy
APPEnvoyproxy1.33.0< 1.30.101.31.0 – 1.31.6 (excl.)1.32.0 – 1.32.4 (excl.)
Related vulnerabilities
Envoy OAuth filter: pominięcie walidacji access tokena umożliwia nieautoryzowany dostęp
Envoy 1.12.0: zapis poza buforami żądania HTTP/2 prowadzący do RCE lub bypass ACL
Bypass mechanizmów kontroli dostępu przez białe znaki w nagłówkach HTTP w Envoy
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can ...
Envoy Proxy: NULL pointer dereference powodujący crash przy braku nagłówka hosta