V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-23323
DEB
Medium

Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage …

CVSS
5.3
Medium
EPSS
0.01
p38
Published
2024-01-01
Updated
2024-01-01
Description

Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Tags · CWE
Pre-auth
CWE-1176
CWE-400
CAPEC-147
CAPEC-227
CAPEC-492
Affected products
Envoy 1.26.0–1.26.7Envoy 1.27.0–1.27.3Envoy 1.28.0–1.28.1Envoy 1.29.0–1.29.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.005 · p38
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
envoyproxyTracked
envoy*Tracked
Source databases
DEB
CVE
Related vulnerabilities