PT-2023-3902 · Envoy · Envoy

Phlax

·

Publicado

2023-07-25

·

Atualizado

2024-03-06

·

CVE-2023-35943

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:S/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.27.0 Envoy versions prior to 1.26.4 Envoy versions prior to 1.25.9 Envoy versions prior to 1.24.10 Envoy versions prior to 1.23.12
Description The issue is related to a use-after-free error in the HTTP CORS filter of the Envoy proxy server. This can be exploited by a remote attacker to perform a denial-of-service (DoS) attack when the origin header is removed between decodeHeaders and encodeHeaders operations.
Recommendations For versions prior to 1.27.0, update to version 1.27.0 or later. For versions prior to 1.26.4, update to version 1.26.4 or later. For versions prior to 1.25.9, update to version 1.25.9 or later. For versions prior to 1.24.10, update to version 1.24.10 or later. For versions prior to 1.23.12, update to version 1.23.12 or later. As a temporary workaround, do not remove the origin header in the Envoy configuration.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04197
BIT-ENVOY-2023-35943
CVE-2023-35943
GHSA-MC6H-6J9X-V3GQ

Produtos afetados

Envoy