CVE Vulnerabilities

CVE-2024-34363

Uncaught Exception

Published: Jun 04, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu

Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception would cause Envoy to crash.

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

Name Vendor Start Version End Version
Envoy Envoyproxy 1.28.0 (including) 1.28.4 (excluding)
Envoy Envoyproxy 1.29.0 (including) 1.29.5 (excluding)
Envoy Envoyproxy 1.30.0 (including) 1.30.2 (excluding)

References