Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-35470

Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 5.8
Products affected by CVE-2020-35470


Contact Us

Shodan ® - All rights reserved