CVE-2019-18817: High severity istio vulnerability
Published Nov 12, 2019
·Updated
Istio 1.3.x before 1.3.5 allows Denial of Service because continueonlistenerfilterstimeout is set to True, a related issue to CVE-2019-18836.
Other sources
Istio 1.3.x before 1.3.5 is vulnerable to denial of service because continueonlistenerfilterstimeout is set to True, a related issue to CVE-2019-18836.
Affected Software
2 affected componentsFixes available
go/istio.io/istio>=1.3.0<1.3.5
1.3.5
Istio Istio>=1.3<1.3.5
Event History
Nov 12, 2019
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
Description
May 24, 2022
Advisory Published
10:01 PM
Frequently Asked Questions
1
What is CVE-2019-18817?
CVE-2019-18817 is a vulnerability in Istio 1.3.x before 1.3.5 that allows denial of service due to the continue_on_listener_filters_timeout being set to True.
2
How does CVE-2019-18817 affect Istio?
CVE-2019-18817 affects Istio versions 1.3.x before 1.3.5.
3
What is the severity of CVE-2019-18817?
The severity of CVE-2019-18817 is high, with a CVSS score of 7.5.
4
How can I fix CVE-2019-18817?
To fix CVE-2019-18817, upgrade Istio to version 1.3.5.
5
Where can I find more information about CVE-2019-18817?
More information about CVE-2019-18817 can be found at the following references: [1] [2] [3]