PT-2021-22419 · Envoy+1 · Envoy+1
Travisgroth
·
Published
2021-09-09
·
Updated
2024-08-21
·
CVE-2021-39162
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Pomerium versions prior to 0.15.1
Description
Pomerium, an open source identity-aware access proxy based on Envoy, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a Denial of Service (DoS) in the presence of untrusted upstream servers. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered.
Recommendations
For versions prior to 0.15.1, update to version 0.15.1, which contains an upgraded Envoy binary with this issue patched.
If only trusted upstreams are configured, there is not substantial risk of this condition being triggered, but it is still recommended to update to version 0.15.1 for maximum security.
Fix
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Envoy
Pomerium