Vulnerability Name: | CVE-2019-18836 (CCN-171294) | ||||||||||||||||
Assigned: | 2019-10-07 | ||||||||||||||||
Published: | 2019-10-07 | ||||||||||||||||
Updated: | 2019-11-12 | ||||||||||||||||
Summary: | Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used." | ||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-835 | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-18836 Source: MISC Type: Vendor Advisory https://blog.envoyproxy.io Source: CCN Type: Envoy Proxy Blog The official Envoy Proxy blog Source: XF Type: UNKNOWN envoy-cve201918836-dos(171294) Source: CCN Type: Envoy GIT Repository Listener Filter Timeout DoS Source: CONFIRM Type: Exploit, Third Party Advisory https://github.com/envoyproxy/envoy/security/advisories/GHSA-3xvf-4396-cj46 Source: CCN Type: istio GIT Repository Istio Sidecar consuming high CPU Istio 1.30-1.3.3 #18229 Source: MISC Type: Exploit, Third Party Advisory https://github.com/istio/istio/issues/18229 Source: MISC Type: Mailing List, Third Party Advisory https://groups.google.com/forum/#!forum/envoy-users | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |