Vulnerabilities > CVE-2022-21655 - Unspecified vulnerability in Envoyproxy Envoy
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of service. As a workaround turn off internal redirects if direct response entries are configured on the same listener.
Vulnerable Configurations
References
- https://github.com/envoyproxy/envoy/commit/177d608155ba8b11598b9bbf8240e90d8c350682
- https://github.com/envoyproxy/envoy/commit/177d608155ba8b11598b9bbf8240e90d8c350682
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-7r5p-7fmh-jxpg
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-7r5p-7fmh-jxpg