PT-2020-13162 · Envoy · Envoy

Antonio Vicente

+1

·

Published

2020-07-01

·

Updated

2024-03-06

·

CVE-2020-12603

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy versions 1.14.2, 1.13.2, 1.12.4 or earlier
Description The issue is related to excessive memory consumption when proxying HTTP/2 requests or responses with many small data frames. This occurs when the software handles a large number of 1-byte data frames.
Recommendations For Envoy versions 1.14.2, 1.13.2, 1.12.4 or earlier, consider updating to a version that includes a fix for this issue to prevent excessive memory consumption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-ENVOY-2020-12603
CVE-2020-12603
GHSA-PC38-4Q6C-85P6
OPENSUSE-SU-2022:0065-1
RHSA-2020:2798
RHSA-2020:2864

Affected Products

Envoy