Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, There is a possibility that non compliant HTTP/1 service may allow malformed requests, potentially leading to a bypass of security policies. This issue is fixed in versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9.
Remediation
References
Related Vulnerabilities
WordPress Plugin MainWP Dashboard Unspecified Vulnerability (2.0.22)
Python Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-1015)
WordPress Plugin Vision Interactive For WordPress Cross-Site Scripting (1.4.4)
WordPress Plugin Affiliate Ads for Clickbank Products Cross-Site Scripting (1.6)
WordPress Plugin WP Job Manager Privilege Escalation (1.34.4)