First published: Wed Jul 01 2020(Updated: )
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Envoy Proxy | <=1.12.4 | |
Envoy Proxy | >=1.13.0<=1.13.2 | |
Envoy Proxy | >=1.14.0<=1.14.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8663 is a vulnerability in Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier that may exhaust file descriptors and/or memory when accepting too many connections.
CVE-2020-8663 has a severity rating of 7.5 (high).
CVE-2020-8663 affects Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier by potentially exhausting file descriptors and/or memory when too many connections are accepted.
To fix CVE-2020-8663, you should upgrade Envoy to a version later than 1.14.2, 1.13.2, or 1.12.4.
You can find more information about CVE-2020-8663 in the GitHub Security Advisory (GHSA-v8q7-fq78-4997) and the Envoy documentation.