PT-2022-3386 · Envoy · Envoy

Shachar Menashe

·

Published

2022-06-09

·

Updated

2024-03-06

·

CVE-2022-29225

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.22.1
Description The issue is related to the decode/encodeBody component of the Envoy proxy, which can lead to uncontrolled resource consumption. An attacker can exploit this by sending a specially crafted zip file, potentially causing a denial of service due to system memory exhaustion. This can be achieved by zip bombing the decompressor, where a small highly compressed payload is sent.
Recommendations For versions prior to 1.22.1, users are advised to upgrade to a newer version to resolve the issue. As a temporary workaround, consider disabling decompression for users unable to upgrade.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2022-04157
BIT-ENVOY-2022-29225
CVE-2022-29225
GHSA-75HV-2JJJ-89HH
RHSA-2022:5003
RHSA-2022:5004

Affected Products

Envoy