Description
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This can result in a DoS condition. Pomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1989 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This can result in a DoS condition. Pomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched. |
Github GHSA |
GHSA-5wjf-62hw-q78r | Excessive CPU usage |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T01:58:18.254Z
Reserved: 2021-08-16T00:00:00.000Z
Link: CVE-2021-39204
No data.
Status : Modified
Published: 2021-09-09T22:15:09.773
Modified: 2024-11-21T06:18:53.640
Link: CVE-2021-39204
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA