Incorrect Downstream Address Logging Vulnerability in Envoy

Incorrect Downstream Address Logging Vulnerability in Envoy

CVE-2020-35470 · HIGH Severity

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).

Learn more about our Network Penetration Testing.