Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafted packet, an attacker could trigger a Null Pointer Exception resulting in a Denial of Service. This could be sent to the ingress gateway or a sidecar, triggering a null pointer exception which results in a denial of service. This also affects servicemesh-proxy where a null pointer exception flaw was found in servicemesh-proxy. When running Telemetry v2 (not on by default in version 1.4.x), an attacker could send a specially crafted packet to the ingress gateway or proxy sidecar, triggering a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade istioUpgrade kernel-uek-containerUpgrade istio-sidecar-injectorUpgrade olcnectlUpgrade kubernetesUpgrade istio-proxy-initUpgrade istio-node-agentUpgrade istio-istioctlUpgrade kata-runtimeUpgrade olcne-prometheus-chartUpgrade kubeletUpgrade olcne-utilsUpgrade istio-pilot-discoveryUpgrade kubectlUpgrade olcneUpgrade kubeadmUpgrade olcne-api-serverUpgrade istio-galleyUpgrade istio-mixsUpgrade istio-mixcUpgrade kataUpgrade olcne-istio-chartUpgrade olcne-nginxUpgrade olcne-agentUpgrade istio-citadelUpgrade kata-imageUpgrade istio-pilot-agent | Jul 23, 2020 | Jun 2, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub