CVE-2019-15225 (High) detected in envoy-wasmae02dc6bdd5c5ea61c3869395d81689e34988156, envoy-wasmae02dc6bdd5c5ea61c3869395d81689e34988156 #2
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2019-15225 - High Severity Vulnerability
Vulnerable Libraries - envoy-wasmae02dc6bdd5c5ea61c3869395d81689e34988156, envoy-wasmae02dc6bdd5c5ea61c3869395d81689e34988156
Vulnerability Details
In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote attacker may send a request with a very long URI to result in a denial of service (memory consumption). This is a related issue to CVE-2019-14993.
Publish Date: 2019-08-19
URL: CVE-2019-15225
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15225
Release Date: 2019-08-19
Fix Resolution: v1.11.2
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: