Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* servers. 0.15.1 contains an upgraded envoy binary with this vulnerability patched. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2061 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* servers. 0.15.1 contains an upgraded envoy binary with this vulnerability patched. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered. |
Github GHSA |
GHSA-gjcg-vrxg-xmgv | Incorrect handling of H2 GOAWAY + SETTINGS frames |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T01:58:18.235Z
Reserved: 2021-08-16T00:00:00.000Z
Link: CVE-2021-39162
No data.
Status : Modified
Published: 2021-09-09T22:15:09.050
Modified: 2024-11-21T06:18:45.580
Link: CVE-2021-39162
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA