CVE Vulnerabilities

CVE-2024-34363

Published: Jun 04, 2024 | Modified: Jun 11, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu

Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception would cause Envoy to crash.

Affected Software

Name Vendor Start Version End Version
Envoy Envoyproxy 1.28.0 (including) 1.28.4 (excluding)
Envoy Envoyproxy 1.29.0 (including) 1.29.5 (excluding)
Envoy Envoyproxy 1.30.0 (including) 1.30.2 (excluding)

References