First published: Thu Oct 01 2020(Updated: )
Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Envoyproxy Envoy | >=2d69e30<3b5acb2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25018 is a vulnerability in Envoy, a popular open-source proxy server, that may fail to parse request URLs requiring host canonicalization.
CVE-2020-25018 has a high severity rating with a CVSS score of 7.5.
Envoy versions between 2d69e30 and 3b5acb2 are affected by CVE-2020-25018.
To fix CVE-2020-25018, update your Envoy proxy server to a version beyond 3b5acb2.
You can find more information about CVE-2020-25018 in the official Envoy security advisories and the Envoy security announcement forum.