VDB
CVE-2022-21654
CVE-2022-21654
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Incorrect configuration handling allows TLS session re-use without re-validation in Envoy
EPSS 1.08% · 63.0th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.08%
63.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | envoy | 1.21.0, 1.20.0, 1.7.0 |
| Bitnami | envoy | 1.19.0, 1.20.0, 1.21.0 |
Timeline
- Feb 22, 2022 CVE Published
- Feb 23, 2022 EPSS Score
- Apr 16, 2022 EPSS Score
- Jun 7, 2022 EPSS Score
- Jul 31, 2022 EPSS Score
- Sep 21, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
- Jan 3, 2023 EPSS Score
- Feb 25, 2023 EPSS Score
- Apr 18, 2023 EPSS Score
- Jun 9, 2023 EPSS Score
- Jul 31, 2023 EPSS Score