CVE-2020-25017
01.10.2020, 17:15
Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoys setCopy() header map API does not replace all existing occurences of a non-inline header.Enginsight
Vendor | Product | Version |
---|---|---|
envoyproxy | envoy | 𝑥 < 1.12.7 |
envoyproxy | envoy | 1.13.0 ≤ 𝑥 < 1.13.4 |
envoyproxy | envoy | 1.14.0 ≤ 𝑥 < 1.14.4 |
envoyproxy | envoy | 1.15.0 ≤ 𝑥 < 1.15.1 |
𝑥
= Vulnerable software versions