Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset the stream.
References
Link | Resource |
---|---|
https://github.com/envoyproxy/envoy/commits/master | Patch Third Party Advisory |
https://github.com/envoyproxy/envoy/security/advisories/GHSA-8hf8-8gvw-ggvx | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-07-01 15:15
Updated : 2024-02-04 21:00
NVD link : CVE-2020-12604
Mitre link : CVE-2020-12604
CVE.ORG link : CVE-2020-12604
JSON object : View
Products Affected
envoyproxy
- envoy
CWE
CWE-401
Missing Release of Memory after Effective Lifetime