Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-31921

Опубликовано: 11 мая 2021
Источник: redhat
CVSS3: 10

Описание

Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration.

An authorization bypass vulnerability was found in istio. When the istio gateway is configured with TLS mode AUTO_PASSTHROUGH, it is possible for a malicious user to bypass the authorization checks and gain access to protected services. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

To determine if a potential istio gateway might be affected by this vulnerability, the same command specified here: https://istio.io/latest/news/security/istio-security-2021-006/ can also be applied to OpenShift ServiceMesh using the oc cli instead of kubectl: $ oc get gateways.networking.istio.io -A -o "custom-columns=NAMESPACE:.metadata.namespace,NAME:.metadata.name,TLS_MODE:.spec.servers[*].tls.mode" NAMESPACE   NAME               TLS_MODE test    test-gateway   As specified in the linked reference, if the TLS_MODE returned is AUTO_PASSTHROUGH then the gateway may be affected.

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1955396istio/istio: authorization bypass when using AUTO_PASSTHROUGH

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration.

CVSS3: 9.8
github
больше 3 лет назад

Istio before 1.8.6 and 1.9.x before 1.9.5, when a gateway is using the AUTO_PASSTHROUGH routing configuration, allows attackers to bypass authorization checks and access unexpected services in the cluster.

oracle-oval
больше 4 лет назад

ELSA-2021-9399: olcne security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-9398: olcne security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-9397: olcne security update (IMPORTANT)

10 Critical

CVSS3