Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Envoyproxy Envoy | 9/6/2022 | 17/6/2026 | Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers, there’s a lifetime bug which can be triggered. If while replaying the request Envoy sends a local reply when the… | |
| Modificada | Crítica (9.1) | 1.3% | — | Envoyproxy Envoy | 9/6/2022 | 17/6/2026 | Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that… | |
| Modificada | Alta (7.5) | 1.6% | — | Envoyproxy Envoy | 9/6/2022 | 17/6/2026 | Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously… | |
| Modificada | Media (5.9) | 1.00% | — | Envoyproxy Envoy | 9/6/2022 | 17/6/2026 | Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a feature which can “hold” (prevent removal) upstream hosts obtained via… | |
| Modificada | Media (6.5) | 1.0% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cluster Discovery Service (CDS) all idle connections established to endpoints in that cluster are disconnected. A recursion was introduced in the procedure of disconnecting idle connections that can… | |
| Modificada | Media (6.5) | 0.52% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certificates it accepts from the peer, either as a TLS client or a TLS server, to only those certificates that contain the necessary extendedKeyUsage (id-kp-serverAuth and… | |
| Modificada | Media (5.9) | 0.67% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the default certificate validation routines has a "type confusion" bug when processing subjectAltNames. This processing allows, for example, an rfc822Name or… | |
| Modificada | Alta (7.5) | 1.1% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of service. As a workaround turn off internal redirects if direct… | |
| Modificada | Crítica (9.8) | 1.1% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to ensure that default tls settings are used. Users are advised to upgrade. | |
| Modificada | Alta (7.5) | 1.1% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config>` and the downstream connection disconnects while the… | |
| Modificada | Alta (7.5) | 0.88% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. Sending a locally generated response must stop further processing of request or response data. Envoy tracks the amount of buffered request and response data and aborts the request if the amount of buffered data is over the limit by… | |
| Modificada | Alta (7.5) | 1.1% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only workaround is to not use regex in the JWT… | |
| Modificada | Alta (8.6) | 1.5% | — | Envoyproxy EnvoyPomerium | 9/9/2021 | 17/6/2026 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorrect routing or authorization policy decisions. With specially crafted requests, incorrect authorization or routing… | |
| Modificada | Alta (7.5) | 1.7% | — | Envoyproxy EnvoyPomerium | 9/9/2021 | 17/6/2026 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This can result in a DoS condition. Pomerium versions 0.14.8 and 0.15.1… | |
| Modificada | Alta (8.6) | 1.6% | — | Envoyproxy EnvoyPomerium | 9/9/2021 | 17/6/2026 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* servers. 0.15.1 contains an upgraded envoy binary with this… | |
| Modificada | Alta (7.5) | 1.3% | — | Envoyproxy Envoy | 24/8/2021 | 17/6/2026 | Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow… | |
| Modificada | Alta (7.5) | 1.2% | — | Envoyproxy Envoy | 24/8/2021 | 17/6/2026 | Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions Envoy transitions a H/2 connection to the CLOSED state when it receives a GOAWAY frame without any streams outstanding. The connection state is transitioned to DRAINING when it receives… | |
| Modificada | Alta (8.3) | 0.95% | — | Envoyproxy Envoy | 24/8/2021 | 17/6/2026 | Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' element as part of the path element. Envoy is configured with an RBAC filter for authorization or similar mechanism with an explicit case of… | |
| Modificada | Alta (7.5) | 1.2% | — | Envoyproxy Envoy | 24/8/2021 | 17/6/2026 | Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy’s procedure for resetting a HTTP/2 stream has O(N^2) complexity, leading to high CPU utilization when a large number of streams are reset. Deployments are susceptible to Denial of… | |
| Modificada | Alta (8.3) | 3.3% | — | Envoyproxy Envoy | 24/8/2021 | 17/6/2026 | Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request headers to the external authorization service it must merge multiple value headers according to the HTTP spec. However, only the last header… | |
| Modificada | Alta (8.8) | 3.1% | — | Enphase Envoy Firmware | 16/6/2021 | 17/6/2026 | An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to execute arbitrary commands via the force parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Enphase Envoy Firmware | 16/6/2021 | 17/6/2026 | An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash of the username and serial number. The serial number can be retrieved by an unauthenticated user… | |
| Modificada | Crítica (9.8) | 2.2% | — | Enphase Envoy Firmware | 16/6/2021 | 17/6/2026 | An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can be retrieved by an unauthenticated user at /info.xml. | |
| Modificada | Media (5.3) | 1.6% | — | Enphase Envoy Firmware | 16/6/2021 | 17/6/2026 | An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accounts are hardcoded values derived from the MD5 hash of the username and serial number mixed with some static strings. The serial number can… | |
| Modificada | Crítica (9.8) | 0.66% | — | Togatech Tenvoy | 16/6/2021 | 17/6/2026 | tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching… |