[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Denial of service vulnerability in getenvoy-envoy - CVE-2024-27919 (rpm)

ID: oval:org.secpod.oval:def:99606Date: (C)2024-04-29   (M)2024-04-29
Class: VULNERABILITYFamily: unix




The host is installed with getenvoy-envoy version 1.29.0 before 1.29.2 and is prone to a denial of service vulnerability. A flaw is present in the application, which fails to properly handle issues in HTTP/2 codec. On successful exploitation, An attacker can to send a sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption.

Platform:
Linux
Product:
getenvoy-envoy
Reference:
CVE-2024-27919
CVE    1
CVE-2024-27919

© SecPod Technologies