Описание
No description is available for this CVE.
Отчет
This CVE has been marked as Rejected by the assigning CNA.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-istio-csr-rhel9 | Fix deferred | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-bundle | Fix deferred | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Fix deferred | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-acmesolver-rhel9 | Fix deferred | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-rhel9 | Fix deferred | ||
| ExternalDNS Operator | edo/external-dns-rhel8 | Fix deferred | ||
| ExternalDNS Operator | edo/external-dns-rhel9 | Fix deferred | ||
| OpenShift Serverless | openshift-serverless-1/kn-eventing-istio-controller-rhel9 | Fix deferred | ||
| OpenShift Serverless | openshift-serverless-1/net-istio-controller-rhel9 | Fix deferred | ||
| OpenShift Serverless | openshift-serverless-1/net-istio-webhook-rhel9 | Fix deferred |
Показывать по
10
Дополнительная информация
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2430117istio: Istio: Firewall rule injection via annotation allows limited integrity impact
Связанные уязвимости
nvd
2 месяца назад
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVSS3: 4.1
github
2 месяца назад
Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the traffic.sidecar.istio.io/excludeInterfaces annotation. NOTE: the reporter's position is "this doesn't represent a security vulnerability (pod creators can already exclude sidecar injection entirely)."