Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on earlier versions. continueDecoding() shouldn’t ever be called from filters after a local reply has been sent. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade olcne-olm-chartUpgrade olcne-oci-csi-chartUpgrade olcne-agentUpgrade kubeadmUpgrade olcnectlUpgrade olcne-metallb-chartUpgrade kataUpgrade istio-istioctlUpgrade istioUpgrade olcne-nginxUpgrade kubeletUpgrade olcne-gluster-chartUpgrade cri-oUpgrade kubectlUpgrade etcdUpgrade olcne-prometheus-chartUpgrade olcne-api-serverUpgrade olcne-utilsUpgrade olcne-istio-chartUpgrade cri-toolsUpgrade olcne-grafana-chartUpgrade olcne-oci-ccm-chart | Jul 12, 2022 | Jun 9, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub