PT-2024-25822 · Envoy · Envoy

·

CVE-2024-34364

·

Published

2024-06-04

·

Updated

2024-07-11

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy (affected versions not specified)
Description The issue is related to an out-of-memory (OOM) vector exposed by Envoy, a cloud-native, open source edge and service proxy. This occurs because the async HTTP client buffers the response with an unbounded buffer, specifically from the mirror response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ENVOY-2024-34364
CVE-2024-34364
GHSA-XCJ3-H7VF-FW26

Affected Products

Envoy