Related Vulnerabilities: CVE-2022-29227  

A flaw was found in Envoy. Internal redirects for requests with bodies or trailers are not safe if the redirect prompts an Envoy-generated local reply. A remote attacker can exploit this to cause a denial of service.

Description

A flaw was found in Envoy. Internal redirects for requests with bodies or trailers are not safe if the redirect prompts an Envoy-generated local reply. A remote attacker can exploit this to cause a denial of service.

Additional Information

  • Bugzilla 2088741: CVE-2022-29227 envoy: Internal redirect crash for requests with body/trailers
  • CWE-416: Use After Free
  • FAQ: Frequently asked questions about CVE-2022-29227