First published: Tue Feb 22 2022(Updated: )
A flaw was found in istio. This flaw allows an attacker to send a specially crafted message to isitiod, causing the control plane to crash.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/servicemesh | <0:2.0.9-3.el8 | 0:2.0.9-3.el8 |
redhat/servicemesh | <0:2.1.2-4.el8 | 0:2.1.2-4.el8 |
redhat/Istio | <1.13.1 | 1.13.1 |
redhat/Istio | <1.12.4 | 1.12.4 |
redhat/Istio | <1.11.7 | 1.11.7 |
Istio Istio | <1.11.7 | |
Istio Istio | >=1.12.0<1.12.4 | |
Istio Istio | >=1.13.0<1.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23635 is a vulnerability in the Istio control plane that allows a malicious attacker to crash the control plane by sending a specially crafted message.
CVE-2022-23635 affects the Istio control plane, specifically the `istiod` component.
The severity of CVE-2022-23635 is rated as high (7.5).
You can fix CVE-2022-23635 by updating to Istio version 1.11.7, 1.12.4, or 1.13.1 or higher, depending on the affected version.
You can find more information about CVE-2022-23635 at the following references: [CVE Details](https://www.cve.org/CVERecord?id=CVE-2022-23635), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-23635), [Istio Security Advisory](https://istio.io/latest/news/security/istio-security-2022-003), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2057277), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2022:1276).