Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade olcne-api-serverUpgrade istio-pilot-agentUpgrade olcne-olm-chartUpgrade kubectlUpgrade olcne-utilsUpgrade istio-istioctlUpgrade olcne-istio-chartUpgrade kubeadmUpgrade olcne-grafana-chartUpgrade istioUpgrade olcne-agentUpgrade kubeletUpgrade istio-pilot-discoveryUpgrade olcne-prometheus-chartUpgrade olcne-nginxUpgrade olcnectl | Aug 7, 2021 | Jun 2, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub