PT-2021-22419 · Envoy+1 · Envoy+1

Travisgroth

·

Published

2021-09-09

·

Updated

2024-08-21

·

CVE-2021-39162

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pomerium versions prior to 0.15.1
Description Pomerium, an open source identity-aware access proxy based on Envoy, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a Denial of Service (DoS) in the presence of untrusted upstream servers. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered.
Recommendations For versions prior to 0.15.1, update to version 0.15.1, which contains an upgraded Envoy binary with this issue patched. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered, but it is still recommended to update to version 0.15.1 for maximum security.

Fix

DoS

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ENVOY-2021-39162
CVE-2021-39162
GHSA-GJCG-VRXG-XMGV
GHSA-J374-MJRW-VVP8
GO-2022-0933

Affected Products

Envoy
Pomerium