Exploit maturity not defined.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade envoyproxy/envoy
to version 1.26.7, 1.27.3, 1.28.1, 1.29.1 or higher.
Affected versions of this package are vulnerable to Use After Free due to the improper handling of certain timeouts that occur simultaneously.
Note:
This is only exploitable if hedge_on_per_try_timeout
is enabled, per_try_idle_timeout
is configured, and per-try-timeout
is set to a value that is equal to or within the backoff interval of per_try_idle_timeout
. This scenario leads to a situation where the application unexpectedly terminates.