Incorrect configuration handling allows mTLS session re-use without re-validation after validation settings have changed
Package
No package listed
Affected versions
1.7.0 and later
Patched versions
1.18.6, 1.19.3, 1.20.2, 1.21.1
CVSSS Score 7.3 AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
tls allows re-use when some cert validation settings have changed
Impact
Resources available to unauthorized users
Patches
Has the problem been patched? What versions should users upgrade to?
Workarounds
Do not modify TLS settings.
References
https://blog.envoyproxy.io
https://github.com/envoyproxy/envoy/releases
For more information
Open an issue in Envoy repo
Email us at envoy-security