In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.
2020-10-01T17:15:13.150
2024-11-21T05:07:15.150
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:N
6.8
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | istio | istio | ≤ 1.5.8 | Yes |
Application | istio | istio | ≤ 1.6.7 | Yes |