CVE-2023-27492: Envoy may crash when a large request body is processed in Lua filter
Attackers can send large request bodies for routes that have Lua filter enabled and trigger crashes.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27492 vulnerability?
CVE-2023-27492 is a vulnerability in Envoy that allows attackers to trigger crashes by sending large request bodies for routes that have the Lua filter enabled.
Which versions of Envoy are affected by CVE-2023-27492?
Envoy versions 1.22.9, 1.23.0 to 1.23.6, 1.24.0 to 1.24.4, and 1.25.0 to 1.25.3 are affected by CVE-2023-27492.
What is the severity of CVE-2023-27492?
The severity of CVE-2023-27492 is medium, with a CVSS score of 6.5.
How can I fix CVE-2023-27492 vulnerability?
To fix the CVE-2023-27492 vulnerability, update to Envoy versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, or 1.22.9 or later.
Where can I find more information about CVE-2023-27492?
You can find more information about CVE-2023-27492 at the following references: [1] GitHub Advisory: https://github.com/envoyproxy/envoy/security/advisories/GHSA-wpc2-2jp6-ppg2 [2] Red Hat Security Advisory: https://access.redhat.com/errata/RHSA-2023:4623 [3] Red Hat CVE page: https://access.redhat.com/security/cve/cve-2023-27492