Istio

Istio

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 19.01.2022 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization policy with hosts and notHosts might be accidentally bypassed for ALLOW action or rejected unexpectedly for DENY action during the up...

  • EPSS 0.24%
  • Veröffentlicht 24.08.2021 23:15:10
  • Zuletzt bearbeitet 21.11.2024 06:18:44

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely e...

  • EPSS 0.17%
  • Veröffentlicht 24.08.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:44

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html/rfc4343), ...

  • EPSS 1.84%
  • Veröffentlicht 29.06.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:11:16

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

Exploit
  • EPSS 0.42%
  • Veröffentlicht 02.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:06:30

Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 27.05.2021 05:15:06
  • Zuletzt bearbeitet 21.11.2024 06:06:30

Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based author...

  • EPSS 0.15%
  • Veröffentlicht 29.01.2021 06:15:12
  • Zuletzt bearbeitet 21.11.2024 04:39:44

A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 01.10.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:07:15

In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied acces...

  • EPSS 0.62%
  • Veröffentlicht 02.06.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 04:55:58

Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafted packet, an attacker could trigger a Null Pointer Exception resulting in a Denial of Service. This c...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 15.04.2020 02:15:14
  • Zuletzt bearbeitet 21.11.2024 04:58:34

Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured explicitly (e.g., abc.example.com) is sent to the serv...