CVE-2021-29258 - log back

CVE-2021-29258 edited at 12 May 2021 07:41:45
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ Envoy before version 1.18.0, and subsequently Istio before version 1.9.3, contains a remotely exploitable vulnerability where an HTTP2 request with an empty metadata map can cause a crash.
References
+ https://istio.io/latest/news/security/istio-security-2021-003/
+ https://github.com/envoyproxy/envoy/commit/e7c114224f75571fc64542c4e641a73768e2df71
CVE-2021-29258 created at 12 May 2021 07:32:15
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes