First published: Wed Mar 24 2021(Updated: )
An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/envoyproxy/envoy | <1.17.2 | 1.17.2 |
Envoy Proxy | =1.14.6 | |
Envoy Proxy | =1.15.3 | |
Envoy Proxy | =1.16.2 | |
Envoy Proxy | =1.17.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29258 is a vulnerability discovered in Envoy 1.14.0 that allows for a remotely exploitable crash for HTTP2 Metadata.
CVE-2021-29258 has a severity rating of 7.5 (high).
CVE-2021-29258 occurs when an empty METADATA map triggers a Reachable Assertion in Envoy.
Envoy versions 1.14.6, 1.15.3, 1.16.2, and 1.17.1 are affected by CVE-2021-29258.
To fix CVE-2021-29258, upgrade to Envoy version 1.17.2 or later.