Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-35470

Опубликовано: 15 дек. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 5.8
EPSS Низкий

Описание

Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
Версия до 1.16.1 (исключая)

EPSS

Процентиль: 73%
0.00781
Низкий

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
redhat
около 5 лет назад

Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).

CVSS3: 8.8
debian
около 5 лет назад

Envoy before 1.16.1 logs an incorrect downstream address because it co ...

github
больше 3 лет назад

Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).

EPSS

Процентиль: 73%
0.00781
Низкий

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo