Vulnerability identifier: #VU25838
Vulnerability risk: High
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-284
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
envoy
Server applications /
IDS/IPS systems, Firewalls and proxy servers
Vendor: Cloud Native Computing Foundation
Description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions when using SDS with Combined Validation Context. A remote attacker can use the same secret (e.g. trusted CA) across many resources together with the combined validation context and gain unauthorized access to the affected application
Mitigation
Install update from vendor's website.
Vulnerable software versions
envoy: 1.0.0 - 1.13.0
CPE
External links
http://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8
http://www.envoyproxy.io/docs/envoy/v1.13.1/intro/version_history
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?