CVE-2020-8661: High severity CNCF Envoy vulnerability
A vulnerability was found in Envoy version 1.13.0 or earlier may consume excessive amounts of memory when responding internally to pipelined requests.
Other sources
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/envoyto a version that resolves this vulnerability.Fixed in 1.13.1
Event History
Frequently Asked Questions
What is CVE-2020-8661?
CVE-2020-8661 refers to a vulnerability in CNCF Envoy through 1.13.0 that may consume excessive amounts of memory when responding internally to pipelined requests.
How severe is CVE-2020-8661?
CVE-2020-8661 has a severity score of 7.5, which is considered high.
Which software versions are affected by CVE-2020-8661?
CNCF Envoy versions up to and including 1.13.0, Redhat Openshift Service Mesh version 1.0.9.
How can I fix CVE-2020-8661?
To fix CVE-2020-8661, upgrade to CNCF Envoy version 1.13.1 or higher.
Where can I find more information about CVE-2020-8661?
You can find more information about CVE-2020-8661 at the following references: <a href="https://access.redhat.com/errata/RHSA-2020:0734">Red Hat advisory</a>, <a href="https://github.com/envoyproxy/envoy/security/advisories/GHSA-36cq-ww7h-p4j7">Envoy security advisory</a>, <a href="https://www.envoyproxy.io/docs/envoy/v1.13.1/intro/version_history">Envoy version history</a>.