CVE-2020-8663: High severity envoy proxy vulnerability
Published Jul 1, 2020
·Updated
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.
Affected Software
3 affected components
Envoyproxy Envoy<=1.12.4
Envoyproxy Envoy>=1.13.0<=1.13.2
Envoyproxy Envoy>=1.14.0<=1.14.2
Event History
Jul 1, 2020
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
Description
Frequently Asked Questions
1
What is CVE-2020-8663?
CVE-2020-8663 is a vulnerability in Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier that may exhaust file descriptors and/or memory when accepting too many connections.
2
How severe is CVE-2020-8663?
CVE-2020-8663 has a severity rating of 7.5 (high).
3
How does CVE-2020-8663 affect Envoy?
CVE-2020-8663 affects Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier by potentially exhausting file descriptors and/or memory when too many connections are accepted.
4
How can I fix CVE-2020-8663?
To fix CVE-2020-8663, you should upgrade Envoy to a version later than 1.14.2, 1.13.2, or 1.12.4.
5
Where can I find more information about CVE-2020-8663?
You can find more information about CVE-2020-8663 in the GitHub Security Advisory (GHSA-v8q7-fq78-4997) and the Envoy documentation.