📦 Istio

by Istio

🔍 What is Istio?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-31921

CRITICAL CVSS 9.8 Jun 2, 2021

This vulnerability allows external clients to bypass Istio's authorization checks and access internal Kubernetes services they shouldn't have access to. It affects Istio deployments where gateways are...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2022-24726

HIGH CVSS 7.5 Mar 10, 2022

CVE-2022-24726 is a denial-of-service vulnerability in Istio's control plane (istiod) where a specially crafted message to the validating webhook endpoint on port 15017 can crash the control plane. Th...

CVE-2021-39156

HIGH CVSS 8.1 Aug 24, 2021

This vulnerability allows attackers to bypass Istio's URI path-based authorization policies by sending HTTP requests with URL fragments (#fragment) in the path. This affects all Istio deployments usin...