Description
Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).
Remediation
References
Related Vulnerabilities
WordPress Plugin PictPress 'resize.php' Multiple Local File Include Vulnerabilities (1.0)
Rukovoditel Cleartext Storage of Sensitive Information Vulnerability (CVE-2020-11821)
Jenkins Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2024-47803)