CVE-2020-8664Improper Authentication in Envoy

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 39.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 4

Description

CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined validation context could lead to the “static” part of the validation context to be not applied, even though it was visible in the active config dump.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDcncf/envoy1.13.0

🔴Vulnerability Details

1
CVEList
CVE-2020-8664: CNCF Envoy through 12020-03-04

📋Vendor Advisories

1
Red Hat
envoy: Incorrect Access Control when using SDS with Combined Validation Context2020-03-03

💬Community

1
Bugzilla
CVE-2020-8664 envoy: Incorrect Access Control when using SDS with Combined Validation Context2020-02-13
CVE-2020-8664 — Improper Authentication in Cncf Envoy | cvebase