CVE-2023-44487
- EPSS 94.44%
- Published 10.10.2023 14:15:10
- Last modified 11.06.2025 17:29:54
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-39388
- EPSS 0.17%
- Published 10.11.2022 20:15:10
- Last modified 21.11.2024 07:18:11
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. ...
CVE-2022-39278
- EPSS 0.1%
- Published 13.10.2022 23:15:11
- Last modified 21.11.2024 07:17:56
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing er...
CVE-2022-31045
- EPSS 0.43%
- Published 09.06.2022 21:15:07
- Last modified 21.11.2024 07:03:46
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most l...
CVE-2022-24726
- EPSS 0.41%
- Published 10.03.2022 21:15:14
- Last modified 21.11.2024 06:50:57
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which resu...
CVE-2022-23635
- EPSS 0.68%
- Published 22.02.2022 22:15:07
- Last modified 21.11.2024 06:48:59
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which re...
CVE-2022-21701
- EPSS 0.23%
- Published 19.01.2022 22:15:09
- Last modified 21.11.2024 06:45:15
Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` permission for `gateways.gateway.networking.k8s.io` objects can escala...
CVE-2022-21679
- EPSS 0.19%
- Published 19.01.2022 22:15:09
- Last modified 21.11.2024 06:45:12
Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts might be accidentally bypassed for ALLOW action or rejected unexpectedly for DENY action during the up...
CVE-2021-39156
- EPSS 0.29%
- Published 24.08.2021 23:15:10
- Last modified 21.11.2024 06:18:44
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely e...
CVE-2021-39155
- EPSS 0.21%
- Published 24.08.2021 23:15:07
- Last modified 21.11.2024 06:18:44
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html/rfc4343), ...