Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade olcnectlUpgrade cri-oUpgrade olcne-agentUpgrade olcne-metallb-chartUpgrade istioUpgrade kubeletUpgrade cri-toolsUpgrade olcne-prometheus-chartUpgrade etcdUpgrade olcne-oci-csi-chartUpgrade kubectlUpgrade olcne-nginxUpgrade olcne-istio-chartUpgrade olcne-olm-chartUpgrade olcne-utilsUpgrade olcne-api-serverUpgrade kataUpgrade istio-istioctlUpgrade olcne-grafana-chartUpgrade olcne-oci-ccm-chartUpgrade olcne-gluster-chartUpgrade kubeadm | Jul 12, 2022 | Jun 9, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub