CVE-2020-8664
Last modified
CVE-2020-8664 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. EPSS estimates a 1.30% chance of exploitation in the next 30 days.
Description
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined validation context could lead to the “static” part of the validation context to be not applied, even though it was visible in the active config dump.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cncf | Envoy | <= 1.13.0 |
References
- https://access.redhat.com/errata/RHSA-2020:0734Third Party Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8Third Party Advisory
- https://www.envoyproxy.io/docs/envoy/v1.13.1/intro/version_historyRelease Notes, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0734Third Party Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8Third Party Advisory
- https://www.envoyproxy.io/docs/envoy/v1.13.1/intro/version_historyRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8664?
How severe is CVE-2020-8664?
How do I fix CVE-2020-8664?
Are you affected by CVE-2020-8664?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
