HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy
Published Dec 18, 2024
7.1
HIGHCVSS 3.1
EPSS 0.62%
Description
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.
Affected products
-
Affected
- ≥ 1.31.0, < 1.31.5
- ≥ 1.32.0, < 1.32.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Envoyproxy | Envoy | unknown | Affected
|
- ≥ 1.31.0 · < 1.31.5
- ≥ 1.32.0 · ≤ 1.32.3
No data.
OpenShift Service Mesh 2
openshift-service-mesh/istio-cni-rhel8
Affected
OpenShift Service Mesh 2
openshift-service-mesh/pilot-rhel8
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/proxyv2-rhel8
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/proxyv2-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-cni-rhel8 | Affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/pilot-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/proxyv2-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/proxyv2-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated Important due to Envoy's improper handling of HTTP 1.1 non-101 1xx responses, potentially leading to downstream failures in networked devices, this issue can disrupt service communication, requiring prompt attention and resolution to maintain network stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2024-53271 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333078 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-51926 Advisory
- https://github.com/envoyproxy/envoy/commit/da56f6da63079baecef9183436ee5f4141a59af8 x_refsource_MISCPatch
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-rmm5-h2wv-mg4f exploitx_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-53271
- https://www.cve.org/CVERecord?id=CVE-2024-53271
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-53271 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2333078 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-51926 | Advisory | |
| https://github.com/envoyproxy/envoy/commit/da56f6da63079baecef9183436ee5f4141a59af8 | x_refsource_MISCPatch | |
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-rmm5-h2wv-mg4f | exploitx_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-53271 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-53271 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data