Описание
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue. There are no known workarounds.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.15.0 (включая) до 1.15.2 (включая)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00057
Низкий
7.6 High
CVSS3
3.5 Low
CVSS3
Дефекты
CWE-863
CWE-863
Связанные уязвимости
CVSS3: 7.6
github
около 3 лет назад
Istio may allow identity impersonation if user has localhost access
EPSS
Процентиль: 18%
0.00057
Низкий
7.6 High
CVSS3
3.5 Low
CVSS3
Дефекты
CWE-863
CWE-863