CVE-2020-25017
01.10.2020, 17:15
Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoys setCopy() header map API does not replace all existing occurences of a non-inline header.Enginsight
| Vendor | Product | Version |
|---|---|---|
| envoyproxy | envoy | 𝑥 < 1.12.7 |
| envoyproxy | envoy | 1.13.0 ≤ 𝑥 < 1.13.4 |
| envoyproxy | envoy | 1.14.0 ≤ 𝑥 < 1.14.4 |
| envoyproxy | envoy | 1.15.0 ≤ 𝑥 < 1.15.1 |
𝑥
= Vulnerable software versions