CVE-2023-35943
- EPSS 0.01%
- Veröffentlicht 25.07.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 08:09:01
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, the CORS filter will segfault and crash Envoy when the `origin` header is removed and deleted betwe...
CVE-2023-35944
- EPSS 0.01%
- Veröffentlicht 25.07.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 08:09:01
Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes in HTTP/2, however, some internal scheme checks are case-sensitive. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12,...
CVE-2023-35941
- EPSS 0.05%
- Veröffentlicht 25.07.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 08:09:01
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, a malicious client is able to construct credentials with permanent validity in some specific scenar...
CVE-2023-35945
- EPSS 0.13%
- Veröffentlicht 13.07.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:09:01
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cle...
CVE-2023-27496
- EPSS 0.02%
- Veröffentlicht 04.04.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:01
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the OAuth filter assumes that a `state` query param is present on any response that looks like an OAu...
CVE-2023-27493
- EPSS 0.01%
- Veröffentlicht 04.04.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:01
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy does not sanitize or escape request properties when generating request headers. This can lead t...
CVE-2023-27492
- EPSS 0.03%
- Veröffentlicht 04.04.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:00
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the Lua filter is vulnerable to denial of service. Attackers can send large request bodies for routes...
CVE-2023-27491
- EPSS 0.01%
- Veröffentlicht 04.04.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:00
Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, There is a possibility that non compl...
CVE-2023-27488
- EPSS 0.02%
- Veröffentlicht 04.04.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:00
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, escalation of privileges is possible when `failure_mode_allow: true` is configured for `ext_authz` fi...
CVE-2023-27487
- EPSS 0.02%
- Veröffentlicht 04.04.2023 16:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:00
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the client may bypass JSON Web Token (JWT) checks and forge fake original paths. The header `x-envoy-...