PT-2023-3902 · Envoy · Envoy

Phlax

·

Published

2023-07-25

·

Updated

2024-03-06

·

CVE-2023-35943

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.27.0 Envoy versions prior to 1.26.4 Envoy versions prior to 1.25.9 Envoy versions prior to 1.24.10 Envoy versions prior to 1.23.12
Description The issue is related to a use-after-free error in the HTTP CORS filter of the Envoy proxy server. This can be exploited by a remote attacker to perform a denial-of-service (DoS) attack when the origin header is removed between decodeHeaders and encodeHeaders operations.
Recommendations For versions prior to 1.27.0, update to version 1.27.0 or later. For versions prior to 1.26.4, update to version 1.26.4 or later. For versions prior to 1.25.9, update to version 1.25.9 or later. For versions prior to 1.24.10, update to version 1.24.10 or later. For versions prior to 1.23.12, update to version 1.23.12 or later. As a temporary workaround, do not remove the origin header in the Envoy configuration.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2023-04197
BIT-ENVOY-2023-35943
CVE-2023-35943
GHSA-MC6H-6J9X-V3GQ

Affected Products

Envoy