Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-31837

Опубликовано: 10 мар. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in Istio. A user of Istio could be impacted if the JSON Web Key Set (JWKS) resolver becomes unavailable or fails to fetch keys. This vulnerability can lead to the exposure of hardcoded default settings, potentially bypassing authentication mechanisms and allowing unauthorized access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-istio-csr-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-bundleAffected
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
ExternalDNS Operatoredo/external-dns-rhel8Not affected
ExternalDNS Operatoredo/external-dns-rhel9Not affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-istio-controller-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/net-istio-controller-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/net-istio-webhook-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1392
https://bugzilla.redhat.com/show_bug.cgi?id=2446344istio: Istio: Information disclosure and authentication bypass via JWKS resolver unavailability

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
17 дней назад

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.

7.5 High

CVSS3