Lucene search

K
osvGoogleOSV:CVE-2020-25017
HistoryOct 01, 2020 - 5:15 p.m.

CVE-2020-25017

2020-10-0117:15:13
Google
osv.dev
3

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

45.3%

Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.

CPENameOperatorVersion
envoyeq1.13.3
envoyeq1.13.2
envoyeq1.13.0
envoyeq1.13.1

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

45.3%