{"api_version":"1","generated_at":"2026-07-24T23:43:48+00:00","cve":"CVE-2022-21654","urls":{"html":"https://cve.report/CVE-2022-21654","api":"https://cve.report/api/cve/CVE-2022-21654.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-21654","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-21654"},"summary":{"title":"CVE-2022-21654","description":"Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to ensure that default tls settings are used. Users are advised to upgrade.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2022-02-22 23:15:00","updated_at":"2022-03-03 18:11:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-5j4x-g36v-m283","name":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-5j4x-g36v-m283","refsource":"CONFIRM","tags":[],"title":"Incorrect configuration handling allows mTLS session re-use without re-validation after validation settings have changed · Advisory · envoyproxy/envoy · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/envoyproxy/envoy/commit/e9f936d85dc1edc34fabd0a1725ec180f2316353","name":"https://github.com/envoyproxy/envoy/commit/e9f936d85dc1edc34fabd0a1725ec180f2316353","refsource":"MISC","tags":[],"title":"CVE-2022-21654 · envoyproxy/envoy@e9f936d · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-21654","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21654","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"21654","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"envoyproxy","cpe5":"envoy","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2022-21654","STATE":"PUBLIC","TITLE":"Incorrect configuration handling allows TLS session re-use without re-validation in Envoy"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"envoy","version":{"version_data":[{"version_value":">= 1.7.0, < 1.18.6"},{"version_value":">= 1.19.0, < 1.19.3"},{"version_value":">= 1.20.0, < 1.20.2"},{"version_value":">= 1.21.0, < 1.21.1"}]}}]},"vendor_name":"envoyproxy"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to ensure that default tls settings are used. Users are advised to upgrade."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-295: Improper Certificate Validation"}]}]},"references":{"reference_data":[{"name":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-5j4x-g36v-m283","refsource":"CONFIRM","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-5j4x-g36v-m283"},{"name":"https://github.com/envoyproxy/envoy/commit/e9f936d85dc1edc34fabd0a1725ec180f2316353","refsource":"MISC","url":"https://github.com/envoyproxy/envoy/commit/e9f936d85dc1edc34fabd0a1725ec180f2316353"}]},"source":{"advisory":"GHSA-5j4x-g36v-m283","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-02-22 23:15:00","lastModifiedDate":"2022-03-03 18:11:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*","versionStartIncluding":"1.21.0","versionEndExcluding":"1.21.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*","versionStartIncluding":"1.20.0","versionEndExcluding":"1.20.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*","versionStartIncluding":"1.19.0","versionEndExcluding":"1.19.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*","versionStartIncluding":"1.7.0","versionEndExcluding":"1.18.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"21654","Ordinal":"221397","Title":"CVE-2022-21654","CVE":"CVE-2022-21654","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"21654","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}