Istio

Istio

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht Exploit
  • EPSS 94.44%
  • Veröffentlicht 10.10.2023 14:15:10
  • Zuletzt bearbeitet 11.06.2025 17:29:54

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • EPSS 0.17%
  • Veröffentlicht 10.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:18:11

Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. ...

  • EPSS 0.1%
  • Veröffentlicht 13.10.2022 23:15:11
  • Zuletzt bearbeitet 21.11.2024 07:17:56

Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing er...

  • EPSS 0.43%
  • Veröffentlicht 09.06.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:46

Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most l...

  • EPSS 0.41%
  • Veröffentlicht 10.03.2022 21:15:14
  • Zuletzt bearbeitet 21.11.2024 06:50:57

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which resu...

  • EPSS 0.68%
  • Veröffentlicht 22.02.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:48:59

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which re...

  • EPSS 0.23%
  • Veröffentlicht 19.01.2022 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:45:15

Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` permission for `gateways.gateway.networking.k8s.io` objects can escala...

  • EPSS 0.19%
  • Veröffentlicht 19.01.2022 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts might be accidentally bypassed for ALLOW action or rejected unexpectedly for DENY action during the up...

  • EPSS 0.29%
  • Veröffentlicht 24.08.2021 23:15:10
  • Zuletzt bearbeitet 21.11.2024 06:18:44

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely e...

  • EPSS 0.21%
  • Veröffentlicht 24.08.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:44

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html/rfc4343), ...