CVE-2022-29226
- EPSS 0.07%
- Published 09.06.2022 20:15:08
- Last modified 21.11.2024 06:58:45
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow shou...
CVE-2022-29228
- EPSS 0.43%
- Published 09.06.2022 20:15:08
- Last modified 21.11.2024 06:58:45
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on e...
CVE-2022-29227
- EPSS 0.33%
- Published 09.06.2022 20:15:08
- Last modified 21.11.2024 06:58:45
Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers, there’s a lifetime bug which can be triggered. If ...
CVE-2022-29225
- EPSS 0.02%
- Published 09.06.2022 20:15:08
- Last modified 21.11.2024 06:58:45
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decomp...
CVE-2022-29224
- EPSS 0.78%
- Published 09.06.2022 19:15:10
- Last modified 21.11.2024 06:58:45
Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a f...
CVE-2022-23606
- EPSS 0.1%
- Published 22.02.2022 23:15:11
- Last modified 21.11.2024 06:48:55
Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cluster Discovery Service (CDS) all idle connections established to endpoints in that cluster are disconnected. A recursion was intr...
CVE-2022-21657
- EPSS 0.04%
- Published 22.02.2022 23:15:11
- Last modified 21.11.2024 06:45:10
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certificates it accepts from the peer, either as a TLS client or a TLS server, to only those certificates ...
CVE-2022-21656
- EPSS 0.02%
- Published 22.02.2022 23:15:11
- Last modified 21.11.2024 06:45:10
Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the default certificate validation routines has a "type confusion" bug when processing subjectAltNames. ...
CVE-2022-21655
- EPSS 0.04%
- Published 22.02.2022 23:15:11
- Last modified 21.11.2024 06:45:09
Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of...
CVE-2022-21654
- EPSS 0.06%
- Published 22.02.2022 23:15:11
- Last modified 21.11.2024 06:45:09
Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to ensure that d...