Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-25014

Опубликовано: 06 нояб. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting in a denial of service to the istio-pilot application).

An out-of-bounds read flaw was found in istio-pilot. This flaw allows an attacker to send a crafted HTTP GET request to the pilot debug API endpoint. This action causes pilot to panic, resulting in a denial of service to the istio pilot application. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0servicemeshNot affected
OpenShift Service Mesh 1.1servicemeshFixedRHSA-2021:132222.04.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-129->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1919066istio-pilot: requests to debug api can result in panic

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 5 лет назад

A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting in a denial of service to the istio-pilot application).

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3