Skip to content

Wrong downstream address logged when using proxy-protocol with tcp-proxy

Moderate
mattklein123 published GHSA-c856-6wpq-9g6g Dec 17, 2020

Package

No package listed

Affected versions

1.16.0

Patched versions

1.16.1

Description

Impact

Incorrect log content. May affect network level RBAC for non-HTTP network connections.

Description

When using proxy-protocol as a listener filter, tcp-proxy as the network filter, and access logging, the wrong downstream address is logged. The logged address should be the one from the proxy protocol header on the connection, but the direct peer address is logged instead.

Patches

1.16.1

Workarounds

None.

References

#14087
#14131

Severity

Moderate

CVE ID

CVE-2020-35470

Weaknesses

No CWEs