← Back

CVE-2020-25017

nvd nist
Published: Oct 1, 2020Modified: Jun 17, 2026

JSON object

Loading...
8.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.7
Source: NVD

Description

Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.

Affected (4)

Products: Envoyproxy: Envoy
1 product
Envoy
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Envoyproxy
Before 1.12.7
From 1.13.0 to 1.13.4
From 1.14.0 to 1.14.4
From 1.15.0 to 1.15.1

References (4)

Timeline

No history available yet.