CVE-2022-21654: high-severity vulnerability in envoyproxy envoy
Incorrect configuration handling allows TLS session re-use without re-validation in Envoy
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Envoy proxy can reuse old TLS connections even after certificate validation settings are changed, allowing encrypted communications to bypass updated security checks. This means security improvements you apply might not actually protect new connections.
Envoy's TLS session resumption mechanism fails to invalidate cached sessions when certificate validation configuration deviates from defaults, enabling session re-use without re-validation of the peer certificate. This affects any deployment with non-default cert validation settings and allows potential man-in-the-middle attacks on resumed sessions.
In the same product, most dangerous first.