ZeroHour

CVE-2024-53271

PoC
CVSS 3.1
7.1 high
EPSS
<1%p48
Published
()
Modified
Description

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.

Vendors
envoyproxy
Products
envoy
Weakness
CWE-670
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

In the news

No ingested article mentions this CVE yet.