Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-34824

Опубликовано: 29 июн. 2021
Источник: redhat
CVSS3: 9.1

Описание

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

A flaw was found in istio. Any client authorized to access Istio XDS API can retrieve any cached gateway TLS certificate and private keys. The highest threat from this vulnerability is to data confidentiality.

Меры по смягчению последствий

This vulnerability can be mitigated by disabling istiod caching. This is controlled by the PILOT_ENABLE_XDS_CACHE environment variable being set to false on istiod. Note: since this disables XDS caching, it may impact the performance of istiod.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemeshNot affected
OpenShift Service Mesh 2.0servicemeshNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1973478istio: istiod propagates user-specified TLS keys and certificates to the secure Istio gateways

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

CVSS3: 8.8
github
больше 3 лет назад

Istio before 1.9.6 and 1.10.x before 1.10.2 has Incorrect Access Control.

oracle-oval
больше 4 лет назад

ELSA-2021-9399: olcne security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-9398: olcne security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-9397: olcne security update (IMPORTANT)

9.1 Critical

CVSS3