Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-34824

Опубликовано: 29 июн. 2021
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

A flaw was found in istio. Any client authorized to access Istio XDS API can retrieve any cached gateway TLS certificate and private keys. The highest threat from this vulnerability is to data confidentiality.

Меры по смягчению последствий

This vulnerability can be mitigated by disabling istiod caching. This is controlled by the PILOT_ENABLE_XDS_CACHE environment variable being set to false on istiod. Note: since this disables XDS caching, it may impact the performance of istiod.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemeshNot affected
OpenShift Service Mesh 2.0servicemeshNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1973478istio: istiod propagates user-specified TLS keys and certificates to the secure Istio gateways

EPSS

Процентиль: 78%
0.01972
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

CVSS3: 8.8
github
около 4 лет назад

Istio before 1.9.6 and 1.10.x before 1.10.2 has Incorrect Access Control.

oracle-oval
около 5 лет назад

ELSA-2021-9399: olcne security update (IMPORTANT)

oracle-oval
около 5 лет назад

ELSA-2021-9398: olcne security update (IMPORTANT)

oracle-oval
около 5 лет назад

ELSA-2021-9397: olcne security update (IMPORTANT)

EPSS

Процентиль: 78%
0.01972
Низкий

9.1 Critical

CVSS3