Vulnerabilities > CVE-2024-34364 - Out-of-bounds Write vulnerability in Envoyproxy Envoy

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
envoyproxy
CWE-787

Summary

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will buffer the response with an unbounded buffer.

Vulnerable Configurations

Part Description Count
Application
Envoyproxy
152

Common Weakness Enumeration (CWE)