Description
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* servers. 0.15.1 contains an upgraded envoy binary with this vulnerability patched. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2061 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* servers. 0.15.1 contains an upgraded envoy binary with this vulnerability patched. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered. |
Github GHSA |
GHSA-gjcg-vrxg-xmgv | Incorrect handling of H2 GOAWAY + SETTINGS frames |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T01:58:18.235Z
Reserved: 2021-08-16T00:00:00.000Z
Link: CVE-2021-39162
No data.
Status : Modified
Published: 2021-09-09T22:15:09.050
Modified: 2026-06-17T04:03:13.447
Link: CVE-2021-39162
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-754
Improper Check for Unusual or Exceptional Conditions
EUVD
Github GHSA