#VU25836 Improper access control in envoy - CVE-2020-8660
Published: March 9, 2020
envoy
Cloud Native Computing Foundation
Description
The vulnerability allows a remote attacker to bypass TLS inspector.
The vulnerability exists due to the TLS extensions (SNI, ALPN) are not inspected, those connections might been matched to a wrong filter chain. A remote attacker can bypass implemented security restrictions in the process and gain unauthorized access to the application.