Vulnerabilities > CVE-2021-43824 - NULL Pointer Dereference vulnerability in Envoyproxy Envoy

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL

Summary

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only workaround is to not use regex in the JWT filter. Users are advised to upgrade.

Vulnerable Configurations

Part Description Count
Application
Envoyproxy
65

Common Weakness Enumeration (CWE)