PT-2022-15010 · Envoy · Envoy
Mattklein123
·
Published
2022-02-22
·
Updated
2024-03-06
·
CVE-2022-21655
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Envoy (affected versions not specified)
Description
The envoy common router will experience a segfault if an internal redirect selects a route configured with direct response or redirect actions, resulting in a denial of service.
Recommendations
As a workaround, turn off internal redirects if direct response entries are configured on the same listener.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Envoy