A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5...
Moderate severity
Unreviewed
Published
Jan 28, 2025
to the GitHub Advisory Database
•
Updated Jan 28, 2025
Description
Published by the National Vulnerability Database
Jan 28, 2025
Published to the GitHub Advisory Database
Jan 28, 2025
Last updated
Jan 28, 2025
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
References