CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have been matched to a wrong filter chain, possibly bypassing some security restrictions in the process.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Envoy | Envoyproxy | * | 1.12.3 (excluding) |
Envoy | Envoyproxy | 1.13.0 (including) | 1.13.1 (excluding) |
OpenShift Service Mesh 1.0 | RedHat | servicemesh-proxy-0:1.0.9-2.el8 | * |