RHSA-2019:4222CriticalCVSS 8.1
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 1.0.3 RPMs security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2019-18801 — envoy: an untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1 CVE-2019-18802 — envoy: malformed request header may cause bypass of route matchers resulting in escalation of privileges or information disclosure CVE-2019-18838 — envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2019:4222
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1773444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1773447
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1773449
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_4222.json