RHSA-2019:4222CriticalCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 1.0.3 RPMs security update

Published
December 11, 2019
Last Modified
June 26, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2019-18801 — envoy: an untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1 CVE-2019-18802 — envoy: malformed request header may cause bypass of route matchers resulting in escalation of privileges or information disclosure CVE-2019-18838 — envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process

🔗 References (6)