CVE-2019-18838

Published: Dic 13, 2019 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2019-8539 Aliases: GSD-2019-18838
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM 5,0
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: none
Availability: partial

Description

AI Translation Available

An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated 'Invalid request' response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that invokes route manager APIs that access a request's Host header causes a NULL pointer dereference, resulting in abnormal termination of the Envoy process.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0010
Percentile
0,3th
Updated

EPSS Score Trend (Last 91 Days)

476

NULL Pointer Dereference

Stable
Common Consequences
Security Scopes Affected:
Availability Integrity Confidentiality
Potential Impacts:
Dos: Crash, Exit, Or Restart Execute Unauthorized Code Or Commands Read Memory Modify Memory
Applicable Platforms
Languages: C, C#, C++, Go, Java
View CWE Details
Application

Envoy by Envoyproxy

Version Range Affected
To 1.12.1 (inclusive)
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://blog.envoyproxy.io
https://github.com/envoyproxy/envoy/commits/master
https://github.com/envoyproxy/envoy/security/advisories/GHSA-f2rv-4w6x-rwhc
https://groups.google.com/forum/#%21forum/envoy-users
https://blog.envoyproxy.io
https://github.com/envoyproxy/envoy/commits/master
https://github.com/envoyproxy/envoy/security/advisories/GHSA-f2rv-4w6x-rwhc
https://groups.google.com/forum/#%21forum/envoy-users