CVE-2020-25017

Published
View on NVD ↗
CVSS v3
8.3
HIGH
CVSS v2
7.5
HIGH
Affected
1
PROJECT

Description

Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.

Cloud-native high-performance edge/middle/service proxy
GitHubGitHub
28.3K