QID 357290
Date Published: 2024-03-06
QID 357290: Amazon Linux Security Advisory for ecs-service-connect-agent : ALAS2023-2024-543
envoy is a high-performance edge/middle/service proxy.
Envoy will crash when certain timeouts happen within the same interval.
The crash occurs when the following are true: 1.
Hedge_on_per_try_timeout is enabled, 2.
Per_try_idle_timeout is enabled (it can only be done in configuration), 3.
Per-try-timeout is enabled, either through headers or configuration and its value is equal, or within the backoff interval of the per_try_idle_timeout.
This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7.
Users are advised to upgrade.
There are no known workarounds for this vulnerability. (
( CVE-2024-23322) envoy is a high-performance edge/middle/service proxy.
The regex expression is compiled for every request and can result in high cpu usage and increased request latency when multiple routes are configured with such matchers.
( CVE-2024-23323) envoy is a high-performance edge/middle/service proxy.
External authentication can be bypassed by downstream connections.
Downstream clients can force invalid grpc requests to be sent to ext_authz, circumventing ext_authz checks when failure_mode_allow is set to true.
( CVE-2024-23324) envoy is a high-performance edge/middle/service proxy.
Envoy crashes in proxy protocol when using an address type that isnt supported by the os.
Envoy is susceptible to crashing on a host with ipv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its ipv6 address.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2023-2024-543 -
alas.aws.amazon.com/AL2023/ALAS-2024-543.html
CVEs related to QID 357290
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2024-543 | amazon linux 2023 |
|