PT-2021-22456 · Envoy+1 · Envoy+1

Travisgroth

·

Published

2021-09-09

·

Updated

2024-03-06

·

CVE-2021-39204

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pomerium versions prior to 0.14.8 Pomerium versions prior to 0.15.1
Description The issue arises from Envoy, which Pomerium is based on, incorrectly handling resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset, resulting in a DoS condition.
Recommendations For versions prior to 0.14.8, update to version 0.14.8 or later to resolve the issue. For versions prior to 0.15.1, update to version 0.15.1 or later to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

BIT-ENVOY-2021-39204
CVE-2021-39204
GHSA-3XH3-33V5-CHCC
GHSA-5WJF-62HW-Q78R

Affected Products

Envoy
Pomerium