CVE-2024-34362

CVSS V2 None CVSS V3 None
Description
Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attacker can exploit this vulnerability by sending a request without `FIN`, then a `RESET_STREAM` frame, and then after receiving the response, closing the connection.
Overview
  • CVE ID
  • CVE-2024-34362
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-06-04T20:59:56.390Z
  • Last Modified Date
  • 2024-06-04T20:59:56.390Z
References
Reference URL Reference Tags
https://github.com/envoyproxy/envoy/security/advisories/GHSA-hww5-43gv-35jv x_refsource_CONFIRM
History
Created Old Value New Value Data Type Notes
2024-06-26 14:33:46 Added to TrackCVE