icon

We found results for “

CVE-2024-34362

Date: June 4, 2024

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in "HttpConnectionManager" (HCM) with "EnvoyQuicServerStream" that can crash Envoy. An attacker can exploit this vulnerability by sending a request without "FIN", then a "RESET_STREAM" frame, and then after receiving the response, closing the connection.

Language: C++

Severity Score

Severity Score

Weakness Type (CWE)

Use After Free

CWE-416

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us