CVE-2021-34824: High severity istio vulnerability
Published Jun 29, 2021
·Updated
Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.
Affected Software
2 affected components
Istio Istio>=1.8.0<1.9.6
Istio Istio>=1.10.0<1.10.2
Event History
Jun 29, 2021
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Istio vulnerability?
The vulnerability ID for this Istio vulnerability is CVE-2021-34824.
2
What is the severity rating of CVE-2021-34824?
CVE-2021-34824 has a severity rating of 8.8 (high).
3
Which versions of Istio are affected by CVE-2021-34824?
Istio versions 1.8.x (1.8.0 to 1.9.5), 1.9.0-1.9.5, and 1.10.0-1.10.1 are affected by CVE-2021-34824.
4
What is the impact of CVE-2021-34824?
CVE-2021-34824 allows unauthorized access to credentials specified in the Gateway and DestinationRule credentialName field in different namespaces.
5
How can I fix CVE-2021-34824?
To fix CVE-2021-34824, update Istio to version 1.9.6 or above for 1.8.x and 1.9.0-1.9.5, and update to version 1.10.2 or above for 1.10.0-1.10.1.