| Vulnerability Name: | CVE-2019-18836 (CCN-171294) | ||||||||||||||||
| Assigned: | 2019-10-07 | ||||||||||||||||
| Published: | 2019-10-07 | ||||||||||||||||
| Updated: | 2019-11-12 | ||||||||||||||||
| Summary: | Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used." | ||||||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||
| Vulnerability Type: | CWE-835 | ||||||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-18836 Source: MISC Type: Vendor Advisory https://blog.envoyproxy.io Source: CCN Type: Envoy Proxy Blog The official Envoy Proxy blog Source: XF Type: UNKNOWN envoy-cve201918836-dos(171294) Source: CCN Type: Envoy GIT Repository Listener Filter Timeout DoS Source: CONFIRM Type: Exploit, Third Party Advisory https://github.com/envoyproxy/envoy/security/advisories/GHSA-3xvf-4396-cj46 Source: CCN Type: istio GIT Repository Istio Sidecar consuming high CPU Istio 1.30-1.3.3 #18229 Source: MISC Type: Exploit, Third Party Advisory https://github.com/istio/istio/issues/18229 Source: MISC Type: Mailing List, Third Party Advisory https://groups.google.com/forum/#!forum/envoy-users | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||