CVE-2020-16844
In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access,…
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Affected
- istio/istio
- Source
- cve@mitre.org
References
- https://github.com/istio/istio/releasesVendor Advisory
- https://istio.io/latest/news/security/istio-security-2020-009/Exploit, Mitigation, Vendor Advisory
- https://github.com/istio/istio/releasesVendor Advisory
- https://istio.io/latest/news/security/istio-security-2020-009/Exploit, Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.