CVE-2024-32976

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:16

Type Values Removed Values Added
References () https://github.com/envoyproxy/envoy/security/advisories/GHSA-7wp5-c2vq-4f8m - Exploit, Third Party Advisory () https://github.com/envoyproxy/envoy/security/advisories/GHSA-7wp5-c2vq-4f8m - Exploit, Third Party Advisory

12 Jun 2024, 14:24

Type Values Removed Values Added
First Time Envoyproxy
Envoyproxy envoy
CPE cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
References () https://github.com/envoyproxy/envoy/security/advisories/GHSA-7wp5-c2vq-4f8m - () https://github.com/envoyproxy/envoy/security/advisories/GHSA-7wp5-c2vq-4f8m - Exploit, Third Party Advisory

05 Jun 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) Envoy es un proxy de servicio y borde de código abierto, nativo de la nube. Envoyproxy con un filtro Brotli puede entrar en un bucle sin fin durante la descompresión de datos Brotli con entrada adicional.

04 Jun 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-04 21:15

Updated : 2024-11-21 09:16


NVD link : CVE-2024-32976

Mitre link : CVE-2024-32976

CVE.ORG link : CVE-2024-32976


JSON object : View

Products Affected

envoyproxy

  • envoy
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')