Redhat

Openshift Service Mesh

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.87%
  • Veröffentlicht 21.12.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:21:55

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

  • EPSS 1.13%
  • Veröffentlicht 27.04.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:19

An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, pos...

Exploit
  • EPSS 3.47%
  • Veröffentlicht 26.03.2020 13:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:20

A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanism...

  • EPSS 1.87%
  • Veröffentlicht 04.03.2020 21:15:11
  • Zuletzt bearbeitet 02.10.2026 21:00:25

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.

  • EPSS 1.89%
  • Veröffentlicht 04.03.2020 21:15:11
  • Zuletzt bearbeitet 02.10.2026 21:00:25

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.

  • EPSS 0.28%
  • Veröffentlicht 17.02.2020 17:15:14
  • Zuletzt bearbeitet 21.11.2024 05:11:12

An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this f...

  • EPSS 2.61%
  • Veröffentlicht 12.02.2020 15:15:14
  • Zuletzt bearbeitet 21.11.2024 05:39:05

Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be on...

  • EPSS 25.45%
  • Veröffentlicht 13.08.2019 21:15:13
  • Zuletzt bearbeitet 14.01.2025 19:29:55

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONT...

  • EPSS 27.89%
  • Veröffentlicht 13.08.2019 21:15:12
  • Zuletzt bearbeitet 14.01.2025 19:29:55

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so...

  • EPSS 56.26%
  • Veröffentlicht 13.08.2019 21:15:12
  • Zuletzt bearbeitet 14.01.2025 19:29:55

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater h...