#VU25838 Improper access control in envoy - CVE-2020-8664
Published: March 9, 2020
envoy
Cloud Native Computing Foundation
Description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions when using SDS with Combined Validation Context. A remote attacker can use the same secret (e.g. trusted CA) across many resources together with the combined validation context and gain unauthorized access to the affected application