CVE-2023-27493
- EPSS 0.01%
- Veröffentlicht 04.04.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:01
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy does not sanitize or escape request properties when generating request headers. This can lead t...
CVE-2023-27492
- EPSS 0.03%
- Veröffentlicht 04.04.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:00
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the Lua filter is vulnerable to denial of service. Attackers can send large request bodies for routes...
CVE-2023-27491
- EPSS 0.01%
- Veröffentlicht 04.04.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:00
Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, There is a possibility that non compl...
CVE-2023-27488
- EPSS 0.02%
- Veröffentlicht 04.04.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:00
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, escalation of privileges is possible when `failure_mode_allow: true` is configured for `ext_authz` fi...
CVE-2023-27487
- EPSS 0.02%
- Veröffentlicht 04.04.2023 16:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:00
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the client may bypass JSON Web Token (JWT) checks and forge fake original paths. The header `x-envoy-...
CVE-2022-29228
- EPSS 0.43%
- Veröffentlicht 09.06.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:45
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on e...
CVE-2022-29227
- EPSS 0.44%
- Veröffentlicht 09.06.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:45
Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers, there’s a lifetime bug which can be triggered. If ...
CVE-2022-29226
- EPSS 0.08%
- Veröffentlicht 09.06.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:45
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow shou...
CVE-2022-29225
- EPSS 0.09%
- Veröffentlicht 09.06.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:45
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decomp...
CVE-2022-29224
- EPSS 1.03%
- Veröffentlicht 09.06.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:58:45
Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a f...