← Back to CVE List

CVE-2020-8664

Published: 2020-03-04T21:15Z
Last Modified: 2024-11-21T05:39Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined validation context could lead to the “static” part of the validation context to be not applied, even though it was visible in the active config dump. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt