CVE-2020-25017

Publication date

2020-10-01 16:39:40

Family

mitre

State

PUBLISHED

Description

Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.