CVE-2020-8843
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at ingress that can be used to affect policy decisions when Mixer policy selectively applies to a source equal to ingress. To exploit this vulnerability, someone has to encode a source.uid in this header. This feature is disabled by default in Istio 1.3 and 1.4.
Se detectó un problema en Istio versiones 1.3 hasta 1.3.6. En determinadas circunstancias, es posible omitir una política Mixer configurada específicamente. Istio-proxy acepta el encabezado x-istio-attributes en la entrada que puede ser usado para afectar las decisiones de la política cuando la política Mixer se aplica selectivamente a una fuente igual a la entrada. Para explotar esta vulnerabilidad, alguien tiene que codificar un archivo source.uid en este encabezado. Esta funcionalidad está deshabilitada por defecto en Istio versiones 1.3 y 1.4.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-10 CVE Reserved
- 2020-02-14 CVE Published
- 2023-12-19 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/istio/istio/commits/master | 2020-02-19 |
URL | Date | SRC |
---|---|---|
https://istio.io/news/security | 2020-02-19 | |
https://istio.io/news/security/istio-security-2020-002 | 2020-02-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Istio Search vendor "Istio" | Istio Search vendor "Istio" for product "Istio" | >= 1.3.0 <= 1.3.6 Search vendor "Istio" for product "Istio" and version " >= 1.3.0 <= 1.3.6" | - |
Affected
|