Vulnerabilities > Cncf > Envoy

DATE CVE VULNERABILITY TITLE RISK
2020-03-04 CVE-2020-8664 Improper Authentication vulnerability in Cncf Envoy 1.13.0
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.
network
low complexity
cncf CWE-287
5.3
2020-03-04 CVE-2020-8661 Resource Exhaustion vulnerability in multiple products
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
network
low complexity
cncf redhat CWE-400
7.5
2020-03-04 CVE-2020-8659 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.
network
low complexity
cncf redhat debian CWE-770
7.5