Database/Container, Kubernetes & orchestration
Envoy: static validation context silently dropped when a shared SDS secret is used, weakening peer checks
Impact
In Envoy through 1.13.0, using the same SDS secret (for example one trusted CA) across many resources together with a combined validation context could leave the static part of that validation context unapplied, even though a config dump showed it as active. The static part is where operators put the checks that actually constrain a peer - subject alt name matching and similar - so the result is a mesh that accepts certificates it was configured to reject, while the running config looks correct. In a multi-tenant GPU cluster where Envoy is the sidecar or gateway enforcing mTLS between tenant namespaces and the control plane, that turns an identity boundary into a CA-level boundary: any workload holding a cert from the shared CA passes. The config-dump mismatch is the operational sting, because the usual way of verifying policy does not reveal the gap.
Who can reach it
Network, unauthenticated with respect to the intended identity check: any party holding a certificate issued by the shared trusted CA can connect to a listener whose static SAN/identity constraints were dropped. Requires the affected configuration shape - a shared SDS secret plus a combined validation context.
What to do
Upgrade Envoy to 1.13.1 or later (or the service-mesh distribution that embeds it; Red Hat shipped RHSA-2020:0734) and restart or roll the proxies - sidecar rollout means restarting pods, gateways can be drained in place. Before upgrading, audit configurations that pair a shared SDS secret with a combined validation context and give each resource its own validation context if you need the static matchers enforced today.
References
Related entries
- CRI-O: Containers started with non-empty default inheritable capabilitiesCVE-2022-27652 · CRI-OMedium
- Docker / moby: Supplementary groups not set up properlyCVE-2022-36109 · Docker / mobyMedium
- Buildah: Symlink following when reading .containerignore/.dockerignore discloses host filesCVE-2022-4122 · BuildahMedium
- containerd: Supplementary groups not set up correctly inside containersCVE-2023-25173 · containerdMedium
- BuildKit: Malicious client or frontend crashes the BuildKit daemonCVE-2024-23650 · BuildKitMedium
- Argo CD: /api/v1/settings exposes sensitive settings without authenticationCVE-2024-37152 · Argo CDMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.