Envoy Issues Crashing Due to HTTP/2 Codec Bugs
CVE-2024-45807

7.5HIGH

Key Information:

Vendor

Envoy

Status
Vendor
CVE Published:
20 September 2024

What is CVE-2024-45807?

Envoy Proxy, a robust cloud-native edge and service proxy, experiences vulnerabilities due to potential bugs related to stream management within the HTTP/2 codec, specifically the 'oghttp' used in version 1.31. This issue can lead to unexpected crashes of the proxy, resulting in service interruptions. The maintainers of Envoy Proxy have taken corrective action by altering the default settings and addressing the issue in version 1.31.2. Users are strongly encouraged to upgrade to this release to enhance security and ensure stable operation, as there are no known workarounds available to mitigate this risk.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.