
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-15104 is a TLS certificate validation vulnerability discovered in Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0. The vulnerability involves incorrect validation of wildcard DNS Subject Alternative Names (SANs) in TLS certificates, where Envoy would improperly allow a wildcard certificate to apply to multiple subdomain levels (GitHub Advisory).
The vulnerability stems from Envoy's TLS certificate validation logic incorrectly allowing a wildcard DNS Subject Alternative Name to apply to multiple subdomain levels. For example, a certificate with a SAN of *.example.com would incorrectly be allowed to validate against nested.subdomain.example.com, when it should only validate against single-level subdomains like subdomain.example.com. This affects both client certificate validation in mTLS and server certificate validation for upstream connections. The vulnerability has been assigned a CVSS v3.1 base score of 5.4 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N (NVD).
The vulnerability impacts configurations that use verify_subject_alt_name in any Envoy version, or match_subject_alt_names in version 1.14 or later. It is particularly concerning in situations where an untrusted entity can obtain a signed wildcard TLS certificate for a domain of which only a subdomain is intended to be trusted. For example, if an application intends to trust api.mysubdomain.example.com, an attacker with a valid certificate for *.example.com could potentially exploit this vulnerability (GitHub Advisory).
The vulnerability is exploitable in scenarios where an attacker can obtain a signed wildcard TLS certificate for a parent domain when only a specific subdomain should be trusted. The attack requires the ability to obtain valid signed certificates for the target domains (GitHub Advisory).
The vulnerability has been fixed in Envoy versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0. Users are advised to upgrade to these patched versions or later. No workarounds are available for unpatched versions (GitHub Advisory, Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."