漏洞标题
在Lua过滤器中处理大型请求体时,Envoy可能崩溃
漏洞描述信息
当在 Lua 过滤器中处理大型请求体时,Envoy 可能会崩溃
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
漏洞类别
N/A
漏洞标题
Envoy may crash when a large request body is processed in Lua filter
漏洞描述信息
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the Lua filter is vulnerable to denial of service. Attackers can send large request bodies for routes that have Lua filter enabled and trigger crashes.
As of versions versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy no longer invokes the Lua coroutine if the filter has been reset. As a workaround for those whose Lua filter is buffering all requests/ responses, mitigate by using the buffer filter to avoid triggering the local reply in the Lua filter.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
漏洞类别
不加限制或调节的资源分配
漏洞标题
Envoy 安全漏洞
漏洞描述信息
Envoy是一款开源的分布式代理服务器。Lua是LUA团队的一款轻量级、扩展的开源脚本语言。 Envoy 存在安全漏洞,该漏洞源于Lua 过滤器容易受到拒绝服务攻击。
CVSS信息
N/A
漏洞类别
其他