PT-2022-19478 · Envoy · Envoy

Artur Molchanov

·

Published

2022-06-09

·

Updated

2024-03-06

·

CVE-2022-29227

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.22.1
Description The issue is related to a lifetime bug that can be triggered when Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers. If Envoy sends a local reply when the redirect headers are processed, the downstream state indicates that the downstream stream is not complete, leading to a use-after-free error when Envoy attempts to reset the upstream stream.
Recommendations For versions prior to 1.22.1, upgrade to version 1.22.1 or later to resolve the issue. If upgrading is not possible, disable internal redirects to minimize the risk of crashes.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BIT-ENVOY-2022-29227
CVE-2022-29227
GHSA-RM2P-QVF6-PVR6

Affected Products

Envoy