Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23327


Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft the upstream PPv2 header. This occurs when the downstream request has a command type of LOCAL and does not have the protocol block. This issue has been addressed in releases 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.


Published

2024-02-09T23:15:09.647

Last Modified

2024-11-21T08:57:31.030

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application envoyproxy envoy < 1.26.7 Yes
Application envoyproxy envoy < 1.27.3 Yes
Application envoyproxy envoy < 1.28.1 Yes
Application envoyproxy envoy < 1.29.1 Yes

References