VYPR

Bitnami package

envoy

pkg:bitnami/envoy

Vulnerabilities (101)

  • CVE-2021-39162HigSep 9, 2021
    affected < 1.18.4fixed 1.18.4

    Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* servers. 0.15.1 contains an up

  • CVE-2021-32781HigAug 24, 2021
    affected >= 1.16.0, < 1.16.5fixed 1.16.5

    Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generat

  • CVE-2021-32780HigAug 24, 2021
    affected >= 1.18.0, < 1.18.4fixed 1.18.4

    Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions Envoy transitions a H/2 connection to the CLOSED state when it receives a GOAWAY frame without any streams outstanding. The connection state is tr

  • CVE-2021-32779HigAug 24, 2021
    affected >= 1.16.0, < 1.16.5fixed 1.16.5

    Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' element as part of the path element. Envoy is configured with an RBAC filter for authorization or simi

  • CVE-2021-32778MedAug 24, 2021
    affected >= 1.16.0, < 1.16.5fixed 1.16.5

    Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy’s procedure for resetting a HTTP/2 stream has O(N^2) complexity, leading to high CPU utilization when a large number of streams are reset. D

  • CVE-2021-32777HigAug 24, 2021
    affected >= 1.16.0, < 1.16.5fixed 1.16.5

    Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request headers to the external authorization service it must merge multiple value headers according to the HT

  • CVE-2021-29492HigMay 28, 2021
    affected < 1.15.5fixed 1.15.5

    Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g

  • CVE-2021-29258HigMay 20, 2021
    affected >= 1.14.6, < 1.14.7fixed 1.14.7

    An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.

  • CVE-2021-28683HigMay 20, 2021
    affected >= 1.16.2, < 1.16.3fixed 1.16.3

    An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.

  • CVE-2021-28682HigMay 20, 2021
    affected >= 1.14.6, < 1.14.7fixed 1.14.7

    An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.

  • CVE-2021-21378HigMar 11, 2021
    affected >= 1.17.0, < 1.17.1fixed 1.17.1

    Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the `allow_missing

  • CVE-2020-35471HigDec 15, 2020
    affected < 1.16.1fixed 1.16.1

    Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.

  • CVE-2020-35470HigDec 15, 2020
    affected < 1.16.1fixed 1.16.1

    Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).

  • CVE-2020-25017HigOct 1, 2020
    affected < 1.12.7fixed 1.12.7

    Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.

  • CVE-2020-15104MedJul 14, 2020
    affected < 1.12.6fixed 1.12.6

    In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly allow a wildcard DNS Subject Alternative Name apply to multiple subdomains. For example, with a SAN of *.example.com, Envoy would incorrectly allow nested.subdoma

  • CVE-2020-8663HigJul 1, 2020
    affected < 1.12.5fixed 1.12.5

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.

  • CVE-2020-12605HigJul 1, 2020
    affected < 1.12.5fixed 1.12.5

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs.

  • CVE-2020-12604HigJul 1, 2020
    affected < 1.12.5fixed 1.12.5

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset the stream.

  • CVE-2020-12603HigJul 1, 2020
    affected < 1.12.5fixed 1.12.5

    Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i.e. 1 byte) data frames.

  • CVE-2020-11767LowApr 15, 2020
    affected < 1.14.2fixed 1.14.2

    Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured explicitly (e.g., abc.example.com) is sent to the server(s) listening behind *.examp

Page 5 of 6