An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade olcne-prometheus-chartUpgrade istio-pilot-discoveryUpgrade istio-pilot-agentUpgrade olcne-utilsUpgrade kubeadmUpgrade olcne-grafana-chartUpgrade olcne-istio-chartUpgrade istio-istioctlUpgrade olcne-api-serverUpgrade kubectlUpgrade olcne-nginxUpgrade olcne-olm-chartUpgrade kubeletUpgrade istioUpgrade olcnectlUpgrade olcne-agent | Aug 7, 2021 | May 20, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub