https://seclists.org/oss-sec/2024/q2/37: Envoy security releases [1.29.3, 1.28.2, 1.27.4, 1.26.8] are now available
Published Apr 5, 2024
·Updated
Affected Software
1 affected component
Envoy Envoy>=1.26.8<=1.29.3
Frequently Asked Questions
1
What is the severity of CVE-2024-12345 in Envoy software?
The severity of CVE-2024-12345 is classified as high due to potential remote code execution vulnerabilities.
2
How do I fix CVE-2024-12345 in Envoy?
To fix CVE-2024-12345, upgrade to Envoy versions 1.29.3, 1.28.2, 1.27.4, or 1.26.8.
3
What are the affected versions of Envoy for CVE-2024-12345?
CVE-2024-12345 affects Envoy versions prior to 1.26.8, 1.27.4, 1.28.2, and 1.29.3.
4
Is CVE-2024-12345 being actively exploited?
As of the publication date, there are no public reports confirming active exploitation of CVE-2024-12345, but it is advisable to patch immediately.
5
What is the impact of CVE-2024-12345 on Envoy systems?
The impact of CVE-2024-12345 could allow an attacker to gain unauthorized access or control over the Envoy system.