CVE-2022-31045
Ill-formed headers may lead to unexpected behavior in Istio
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and 1.14.1. Users are advised to upgrade. There are no known workarounds for this issue.
Istio es una plataforma abierta para conectar, gestionar y asegurar microservicios. En las versiones afectadas, las cabeceras mal formadas enviadas a Envoy en ciertas configuraciones pueden conducir a un acceso inesperado a la memoria, lo que resulta en un comportamiento indefinido o un bloqueo. Los usuarios están en mayor riesgo si tienen un Gateway de entrada de Istio expuesto al tráfico externo. Esta vulnerabilidad se ha resuelto en las versiones 1.12.8, 1.13.5 y 1.14.1. Se recomienda a los usuarios que actualicen. No hay soluciones conocidas para este problema
A flaw was found in Istio. Memory access violation of ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access, resulting in undefined behavior or crashing.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-18 CVE Reserved
- 2022-06-09 CVE Published
- 2023-12-31 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/istio/istio/security/advisories/GHSA-xwx5-5c9g-x68x | Third Party Advisory | |
https://istio.io/latest/news/security/istio-security-2022-05 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-31045 | 2022-06-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2088819 | 2022-06-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Istio Search vendor "Istio" | Istio Search vendor "Istio" for product "Istio" | < 1.12.8 Search vendor "Istio" for product "Istio" and version " < 1.12.8" | - |
Affected
| ||||||
Istio Search vendor "Istio" | Istio Search vendor "Istio" for product "Istio" | >= 1.13.0 < 1.13.5 Search vendor "Istio" for product "Istio" and version " >= 1.13.0 < 1.13.5" | - |
Affected
| ||||||
Istio Search vendor "Istio" | Istio Search vendor "Istio" for product "Istio" | 1.14.0 Search vendor "Istio" for product "Istio" and version "1.14.0" | - |
Affected
|