Description
Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to ensure that default tls settings are used. Users are advised to upgrade.
Remediation
References
Related Vulnerabilities
WordPress Plugin Video Gallery-Best WordPress YouTube Gallery Multiple Vulnerabilities (1.7.6)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2022-3358)
WordPress Plugin BigBlueButton Cross-Site Scripting (2.2.3)
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-10752)