CVE-2022-21654

HIGH

Envoy 1.7.0-1.18.5 - Improper Certificate Validation in TLS Reuse

Title source: llm
STIX 2.1

Description

Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to ensure that default tls settings are used. Users are advised to upgrade.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/envoyproxy/envoy/security/advisories/GHSA-5j4x-g36v-m283

Scores

CVSS v3 7.4
EPSS 0.0104
EPSS Percentile 59.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (1)
envoyproxy/envoy 1.7.0 - 1.18.6
Published Feb 22, 2022
Tracked Since Feb 18, 2026