CVE-2022-21655
Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will seg
Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of service.
As a workaround turn off internal redirects if direct response entries are configured on the same listener.
HIGH · CVSS 7.5
EPSS 0.0018
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0