PT-2024-25822 · Envoy · Envoy

Paul Ogilby

·

Published

2024-06-04

·

Updated

2024-07-11

·

CVE-2024-34364

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy (affected versions not specified)
Description The issue is related to an out-of-memory (OOM) vector exposed by Envoy, a cloud-native, open source edge and service proxy. This occurs because the async HTTP client buffers the response with an unbounded buffer, specifically from the mirror response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Memory Corruption

Weakness Enumeration

Related Identifiers

BIT-ENVOY-2024-34364
CVE-2024-34364
GHSA-XCJ3-H7VF-FW26

Affected Products

Envoy