Описание
Istio may not check inbound TCP connections against istio-policy
Istio 1.1.x through 1.1.6 has Incorrect Access Control. When disablePolicyChecks is set to false, inbound TCP connections do not generate Check requests to istio-policy and external authorization is not applied.
This behavior is a result of a change to istio/pilot/pkg/networking/plugin/mixer/mixer.go in 1.1.
Пакеты
Наименование
istio.io/istio
go
Затронутые версииВерсия исправления
>= 1.1.0, < 1.1.7
1.1.7
Связанные уязвимости
CVSS3: 7.5
nvd
больше 6 лет назад
Istio 1.1.x through 1.1.6 has Incorrect Access Control.