Database/Container, Kubernetes & orchestration
Envoy: Envoy accepts any peer certificate rather than restricting to configured CAs
CVSS 6.8CVE-2022-21657Container, Kubernetes & orchestrationcurated
Impact
Envoy accepts any peer certificate rather than restricting to configured CAs; mTLS trust bypass
Who can reach it
Unauthenticated network with any valid-looking cert
What to do
Upgrade Envoy; sidecar restart
References
Related entries
- Envoy: No URL path normalization, so `something/../admin` bypasses access controlCVE-2019-9901 · EnvoyMedium
- Envoy: External clients manipulate Envoy internal headers, reaching unauthorized behaviourCVE-2024-45806 · EnvoyMedium
- Envoy: OAuth filter does not validate access tokens, so authentication can be skipped entirelyCVE-2022-29226 · EnvoyCritical
- Envoy: HTTP/2 request writes to the heap outside request buffers when the upstream is HTTP/1CVE-2019-18801 · EnvoyCritical
- Envoy: Header whitespace handling enables request smuggling and authorization bypassCVE-2019-18802 · EnvoyCritical
- Envoy: ext-authz header handling flaw allows bypassing the external authorization serviceCVE-2021-32777 · EnvoyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.