CVE-2024-53269
CVSS 3.1 Score 4.5 of 10 (medium)
Details
Published Dec 18, 2024
CWE ID 670
Summary
CVE-2024-53269 is a vulnerability affecting Envoy, a cloud-native high-performance edge/middle/service proxy. The issue arises when Envoy encounters additional addresses that are not IP addresses during the Happy Eyeballs sorting algorithm process. This leads to a crash in the data plane. To mitigate this issue, users are advised to upgrade to Envoy releases 1.32.2, 1.31.4, or 1.30.8. Alternatively, disabling Happy Eyeballs and adjusting IP configurations can also help.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Envoy
Affected Vendors
- Envoy