Improper access control in envoy - CVE-2020-8664
Published: March 9, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions when using SDS with Combined Validation Context. A remote attacker can use the same secret (e.g. trusted CA) across many resources together with the combined validation context and gain unauthorized access to the affected application
Affected software
Cilium
How to mitigate CVE-2020-8664
Cilium - addressed in versions 1.5.13, 1.6.7, 1.7.1