CVE-2024-23325Uncaught Exception in Envoy

Severity
7.5HIGHNVD
EPSS
0.1%
top 66.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 9

Description

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6 address. It is valid for a client to present its IPv6 address to a target server even though the whole chain is connected via IPv4. This issue has been addressed in released 1.29.1

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5envoyproxy/envoy< 1.26.7+3
NVDenvoyproxy/envoy1.26.01.26.7+3

Patches

📋Vendor Advisories

1
Red Hat
envoy: Envoy crashes when using an address type that isn’t supported by the OS2024-02-09