Vulnerabilities > CVE-2021-29258 - Reachable Assertion vulnerability in Envoyproxy Envoy

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
envoyproxy
CWE-617

Summary

An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.

Vulnerable Configurations

Part Description Count
Application
Envoyproxy
4

Common Weakness Enumeration (CWE)