HIGH
envoy: Resource exhaustion when accepting too many connections
Published Jul 1, 2020
7.5
HIGHCVSS 3.1
EPSS 1.47%
Description
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.
Affected products
No data.
OR
- ≤ 1.12.4
- ≥ 1.13.0 · ≤ 1.13.2
- ≥ 1.14.0 · ≤ 1.14.2
No data.
OpenShift Service Mesh 1.0
servicemesh-proxy-0:1.0.11-1.el8
Fixed · RHSA-2020:2864
OpenShift Service Mesh 1.1
servicemesh-proxy-0:1.1.4-2.el8
Fixed · RHSA-2020:2798
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1.0 | servicemesh-proxy-0:1.0.11-1.el8 | Fixed | RHSA-2020:2864 |
| OpenShift Service Mesh 1.1 | servicemesh-proxy-0:1.1.4-2.el8 | Fixed | RHSA-2020:2798 |
No package ranges for this CVE.
Remediation
Red Hat statement
A uncontrolled resource consumption vulnerability was found in Envoy. An attacker can initiate too many connections to the proxy potentially exhausting file descriptors and/or memory resulting in a denial of service.
Weaknesses (1)
References (8)
- https://access.redhat.com/security/cve/CVE-2020-8663 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1844254 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29511 Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-v8q7-fq78-4997 x_refsource_CONFIRMThird Party Advisory
- https://istio.io/latest/news/security/istio-security-2020-007/
- https://nvd.nist.gov/vuln/detail/CVE-2020-8663
- https://www.cve.org/CVERecord?id=CVE-2020-8663
- https://www.envoyproxy.io/docs/envoy/v1.13.1/intro/version_history x_refsource_MISCRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8663 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1844254 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29511 | Advisory | |
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-v8q7-fq78-4997 | x_refsource_CONFIRMThird Party Advisory | |
| https://istio.io/latest/news/security/istio-security-2020-007/ | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-8663 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-8663 | ||
| https://www.envoyproxy.io/docs/envoy/v1.13.1/intro/version_history | x_refsource_MISCRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 1, 2020
Updated Aug 4, 2024
Reserved Feb 6, 2020
Link CVE-2020-8663
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-29511 Assigner mitre
Published Jul 1, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-29511