Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23323


Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.


Published

2024-02-09T23:15:08.977

Last Modified

2024-11-21T08:57:30.403

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
    CWE-1176
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application envoyproxy envoy < 1.26.7 Yes
Application envoyproxy envoy < 1.27.3 Yes
Application envoyproxy envoy < 1.28.1 Yes
Application envoyproxy envoy < 1.29.1 Yes

References