Improper access control in envoy - CVE-2020-8660
Published: March 9, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass TLS inspector.
The vulnerability exists due to the TLS extensions (SNI, ALPN) are not inspected, those connections might been matched to a wrong filter chain. A remote attacker can bypass implemented security restrictions in the process and gain unauthorized access to the application.
Affected software
Cilium
How to mitigate CVE-2020-8660
Cilium - addressed in versions 1.5.13, 1.6.7, 1.7.1