Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-39156

Опубликовано: 24 авг. 2021
Источник: nvd
CVSS3: 8.1
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploitable vulnerability where an HTTP request with #fragment in the path may bypass Istio’s URI path based authorization policies. Patches are available in Istio 1.11.1, Istio 1.10.4 and Istio 1.9.8. As a work around a Lua filter may be written to normalize the path.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия до 1.9.8 (исключая)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия от 1.10.0 (включая) до 1.10.3 (исключая)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
Версия от 1.11.0 (включая) до 1.11.1 (исключая)

EPSS

Процентиль: 46%
0.00236
Низкий

8.1 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-863
CWE-706

Связанные уязвимости

CVSS3: 8.3
redhat
больше 4 лет назад

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploitable vulnerability where an HTTP request with `#fragment` in the path may bypass Istio’s URI path based authorization policies. Patches are available in Istio 1.11.1, Istio 1.10.4 and Istio 1.9.8. As a work around a Lua filter may be written to normalize the path.

CVSS3: 8.1
github
больше 4 лет назад

Istio Fragments in Path May Lead to Authorization Policy Bypass

EPSS

Процентиль: 46%
0.00236
Низкий

8.1 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-863
CWE-706