CVE-2020-35470
15.12.2020, 01:15
Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).Enginsight
| Vendor | Product | Version |
|---|---|---|
| envoyproxy | envoy | 𝑥 < 1.16.1 |
𝑥
= Vulnerable software versions
References