Description
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset the stream.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2018-11039 Vulnerability (CVE-2018-11039)
WordPress Plugin Jigoshop Unspecified Vulnerability (1.10.5)
WordPress Plugin Buddy Share It Allusers FB YR Arbitrary File Upload (3.2.8)
MyBB CVE-2011-5133 Vulnerability (CVE-2011-5133)
WordPress Cookie Data PHP Code Injection Vulnerability (1.5 - 1.5.1.3)