7.5
CVSSv3

CVE-2020-12604

Published: 01/07/2020 Updated: 21/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset the stream.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

envoyproxy envoy

envoyproxy envoy 1.13.2

envoyproxy envoy 1.14.2

Vendor Advisories

Synopsis Important: Red Hat OpenShift Service Mesh 11 servicemesh-proxy security update Type/Severity Security Advisory: Important Topic An update for servicemesh-proxy is now available for OpenShift Service Mesh 11Red Hat Product Security has rated this update as having a security impact of Important A ...
Synopsis Important: Red Hat OpenShift Service Mesh 10 servicemesh-proxy security update Type/Severity Security Advisory: Important Topic An update for servicemesh-proxy is now available for OpenShift Service Mesh 10Red Hat Product Security has rated this update as having a security impact of Important A ...