First published: Tue Aug 13 2019(Updated: )
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/istio.io/istio | >=1.2.0<1.2.4 | 1.2.4 |
go/istio.io/istio | <1.1.13 | 1.1.13 |
Istio Istio | <1.1.13 | |
Istio Istio | >=1.2.0<1.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14993 is a vulnerability in Istio before 1.1.13 and 1.2.x before 1.2.4 that mishandles regular expressions for long URIs, leading to a denial of service during use of certain APIs.
CVE-2019-14993 has a severity rating of 7.5 (high).
Istio versions before 1.1.13 and 1.2.x before 1.2.4 are affected by CVE-2019-14993.
To fix CVE-2019-14993, update your Istio installation to version 1.1.13 or 1.2.4.
You can find more information about CVE-2019-14993 in the following references: [link1](https://nvd.nist.gov/vuln/detail/CVE-2019-14993), [link2](https://github.com/envoyproxy/envoy/issues/7728), [link3](https://discuss.istio.io/t/upcoming-security-updates-in-istio-1-2-4-and-1-1-13/3383)