Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Users are advised to upgrade. Users unable to upgrade may disable Happy Eyeballs and/or change the IP configuration.
History

Thu, 19 Dec 2024 14:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 18 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Dec 2024 19:30:00 +0000

Type Values Removed Values Added
Description Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Users are advised to upgrade. Users unable to upgrade may disable Happy Eyeballs and/or change the IP configuration.
Title Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoy
Weaknesses CWE-670
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-12-18T21:36:18.888Z

Reserved: 2024-11-19T20:08:14.482Z

Link: CVE-2024-53269

cve-icon Vulnrichment

Updated: 2024-12-18T21:36:14.163Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-18T20:15:24.127

Modified: 2024-12-18T22:15:06.763

Link: CVE-2024-53269

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-12-18T19:12:17Z

Links: CVE-2024-53269 - Bugzilla