CVE-2020-8595
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.
- CVSS 3.1
- 7.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 2.61% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- istio/istio · redhat/openshift service mesh
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2020:0477Third Party Advisory
- https://access.redhat.com/security/cve/cve-2020-8595Mitigation, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-8595Issue Tracking, Mitigation, Third Party Advisory
- https://github.com/istio/istio/commits/masterPatch
- https://istio.io/news/security/Vendor Advisory
- https://istio.io/news/security/istio-security-2020-001/Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0477Third Party Advisory
- https://access.redhat.com/security/cve/cve-2020-8595Mitigation, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-8595Issue Tracking, Mitigation, Third Party Advisory
- https://github.com/istio/istio/commits/masterPatch
- https://istio.io/news/security/Vendor Advisory
- https://istio.io/news/security/istio-security-2020-001/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.