Monday, December 14, 2020
CVE-2020-35470
nist.gov
In: nist.gov
Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters). CVE-2020-35470