ISTIO-SECURITY-2024-002

CVEs reported by Envoy and Go.

Apr 8, 2024

Disclosure Details
CVE(s)CVE-2024-27919
CVE-2024-30255
CVE-2023-45288
CVSS Impact Score7.5 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected ReleasesAll releases prior to 1.19.0
1.19.0 to 1.19.8
1.20.0 to 1.20.4
1.21.0

CVE

Envoy CVEs

Go CVEs

NOTE: At the time of publishing, the CVE was not yet scored or vectored.

Am I Impacted?

You are impacted if you accept HTTP/2 traffic from untrusted sources, which applies to most users. This especially applies if you use a Gateway exposed on the public internet.