CVE-2019-14993: High severity istio vulnerability
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14993?
CVE-2019-14993 is a vulnerability in Istio before 1.1.13 and 1.2.x before 1.2.4 that mishandles regular expressions for long URIs, leading to a denial of service during use of certain APIs.
How severe is CVE-2019-14993?
CVE-2019-14993 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2019-14993?
Istio versions before 1.1.13 and 1.2.x before 1.2.4 are affected by CVE-2019-14993.
How can I fix CVE-2019-14993?
To fix CVE-2019-14993, update your Istio installation to version 1.1.13 or 1.2.4.
Where can I find more information about CVE-2019-14993?
You can find more information about CVE-2019-14993 in the following references: [link1](https://nvd.nist.gov/vuln/detail/CVE-2019-14993), [link2](https://github.com/envoyproxy/envoy/issues/7728), [link3](https://discuss.istio.io/t/upcoming-security-updates-in-istio-1-2-4-and-1-1-13/3383)