Envoy before 1.12.1 allows a remote denial of service...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Nov 11, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 28, 2023
Envoy before 1.12.1 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used.
References