CVE-2024-53269: medium-severity vulnerability in envoyproxy envoy
Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoy
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.5epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Users are advised to upgrade. Users unable to upgrade may disable Happy Eyeballs and/or change the IP configuration.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected products
envoyproxy · envoyRelated CVEs — envoyproxy envoy
In the same product, most dangerous first.
CVE-2024-30255MEDIUMHTTP/2: CPU exhaustion due to CONTINUATION frame floodEPSS 87.8%CVE-2024-27919HIGHHTTP/2: memory exhaustion due to CONTINUATION frame floodEPSS 86.7%CVE-2021-29492HIGHBypass of path matching rules using escaped slash charactersEPSS 66.2%CVE-2021-32777HIGHIncorrect concatenation of multiple value request headers in ext-authz extensionEPSS 3.3%CVE-2021-21378HIGHJWT authentication bypass with unknown issuer tokenEPSS 1.7%CVE-2022-29225HIGHZip bomb vulnerability in EnvoyEPSS 1.6%