Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-43824: Build software better, together

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only workaround is to not use regex in the JWT filter. Users are advised to upgrade.

CVE
#dos#git

Package

No package listed

Affected versions

V1.21.0 and earlier

Patched versions

1.18.6, 1.19.3, 1.20.2, 1.21.1

Description

CVSS Score 6.5 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, Medium

A crafted request crashes Envoy configured with JWT filter safe_regex match

Impact

Denial of Service (crash)

Patches

Has the problem been patched? What versions should users upgrade to?

Workarounds

Not use safe_regex for JWT filter

References

https://blog.envoyproxy.io
https://github.com/envoyproxy/envoy/releases

For more information

Open an issue in Envoy repo
Email us at envoy-security

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907