CVE-2021-31920: Medium severity istio vulnerability
Published May 27, 2021
·Updated
Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorization rules are used.
Affected Software
4 affected componentsFixes available
go/istio.io/istio>=1.9.0<=1.9.4
1.9.5
go/istio.io/istio<1.8.6
1.8.6
Istio Istio<1.8.6
Istio Istio>=1.9.0<1.9.5
Event History
May 27, 2021
CVE Published
via MITRE·04:03 AM
Data Sourced
via MITRE·04:03 AM
Description
May 24, 2022
Advisory Published
07:03 PM