Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, gRPC access loggers using listener's global scope can cause a `use-after-free` crash when the listener is drained. Versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12 have a fix for this issue. As a workaround, disable gRPC access log or stop listener update.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ecs-service-connect-agent | Sep 7, 2023 | Jul 25, 2023 |
| Amazon_linux_2023 | — | Upgrade ecs-service-connect-agent | Feb 17, 2025 | Jul 25, 2023 |
| Oracle_linux | — | Upgrade olcne-nginxUpgrade olcnectlUpgrade olcne-gluster-chartUpgrade olcne-oci-ccm-chartUpgrade olcne-olm-chartUpgrade istioUpgrade olcne-istio-chartUpgrade olcne-kubevirt-chartUpgrade olcne-grafana-chartUpgrade olcne-prometheus-chartUpgrade olcne-calico-chartUpgrade virtctlUpgrade olcne-multus-chartUpgrade istio-istioctlUpgrade olcne-api-serverUpgrade olcne-rook-chartUpgrade olcne-metallb-chartUpgrade olcne-utilsUpgrade olcne-agent | Sep 6, 2023 | Jul 25, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub