7.5
CVSSv2

CVE-2020-25017

Published: 01/10/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 8.3 | Impact Score: 3.7 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Envoy up to and including 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

envoyproxy envoy

Vendor Advisories

Synopsis Moderate: Red Hat OpenShift Service Mesh 11 servicemesh-proxy security update Type/Severity Security Advisory: Moderate Topic An update for servicemesh-proxy is now available for OpenShift Service Mesh 11Red Hat Product Security has rated this update as having a security impact of Moderate A Co ...