Description
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on earlier versions. continueDecoding() shouldn’t ever be called from filters after a local reply has been sent. Users are advised to upgrade. There are no known workarounds for this issue.
Remediation
References
Related Vulnerabilities
WordPress Plugin MailPoet Newsletters (Previous) Unspecified Vulnerability (2.7.8)
Python Incorrect Type Conversion or Cast Vulnerability (CVE-2020-10735)
WordPress Plugin Google Doc Embedder SQL Injection (2.5.16)
MySQL CVE-2012-3177 Vulnerability (CVE-2012-3177)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-17858)