GHSA-cf3q-gqg7-3fm9
Envoy crashes when HTTP ext_proc processes local replies
Quick fix
GHSA-cf3q-gqg7-3fm9 — github.com/envoyproxy/envoy: upgrade to the fixed version with the command below.
go get github.com/envoyproxy/envoy@v1.30.10Details
### Summary Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the fail of a websocket handshake will trigger a local reply leading to the crash of Envoy.
### PoC If both websocket and ext_proc are enabled, a failed handshake will trigger a local reply, thus ext_proc will crash.
### Mitigation 1. Disable websocket traffic 2. Change the websocket response from backend to always return `101 Switch protocol` based on RFC. 3. Apply the patch and the ext_proc filter will not send the local reply that is generated by Envoy to the ext_proc server for processing. 4. Apply the patch that the router will cancel the upstream requests when sending a local reply.
### Impact Denial of service
### Reporter Vasilios Syrakis Fernando Cainelli
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.30.10go get github.com/envoyproxy/envoy@v1.30.101.31.0Fixed in: 1.31.6go get github.com/envoyproxy/envoy@v1.31.61.32.0Fixed in: 1.32.4go get github.com/envoyproxy/envoy@v1.32.41.33.0Fixed in: 1.33.1go get github.com/envoyproxy/envoy@v1.33.1