CVE-2020-8660: Medium severity Envoyproxy Envoy vulnerability
A vulnerability was found in Envoy. where TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have been matched to a wrong filter chain, possibly bypassing some security restrictions in the process.
Other sources
CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have been matched to a wrong filter chain, possibly bypassing some security restrictions in the process.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/envoyto a version that resolves this vulnerability.Fixed in 1.13.1
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8660?
The severity of CVE-2020-8660 is medium with a CVSS score of 5.3.
How can I fix CVE-2020-8660?
To fix CVE-2020-8660, upgrade to Envoy version 1.13.1 or higher.
What is the affected software for CVE-2020-8660?
The affected software for CVE-2020-8660 is Envoy versions up to and including 1.13.0.
Are there any known exploits for CVE-2020-8660?
There are no known exploits for CVE-2020-8660 at this time.
Where can I find more information about CVE-2020-8660?
You can find more information about CVE-2020-8660 in the Red Hat Security Advisory RHSA-2020:0734 and the EnvoyProxy GitHub security advisory GHSA-c4g8-7grc-5wvx.