CVE-2022-39278
Istio vulnerable to denial of service attack due to Golang Regex Library
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted or oversized message which results in the control plane crashing when the Kubernetes validating or mutating webhook service is exposed publicly. This endpoint is served over TLS port 15017, but does not require any authentication from the attacker. For simple installations, Istiod is typically only reachable from within the cluster, limiting the blast radius. However, for some deployments, especially external istiod topologies, this port is exposed over the public internet. Versions 1.15.2, 1.14.5, and 1.13.9 contain patches for this issue. There are no effective workarounds, beyond upgrading. This bug is due to an error in `regexp.Compile` in Go.
Istio es una malla de servicios abierta e independiente de la plataforma que proporciona administración de tráfico, aplicación de políticas y recopilación de telemetría. En versiones anteriores a 1.15.2, 1.14.5, y 1.13.9, el plano de control de Istio, istiod, es vulnerable a un error de procesamiento de peticiones, permitiendo a un atacante malicioso que envíe un mensaje especialmente diseñado o de gran tamaño que resulte en el bloqueo del plano de control cuando el servicio de webhooks de comprobación o mutación de Kubernetes está expuesto públicamente. Este endpoint es servido a través del puerto 15017 de TLS, pero no requiere ninguna autenticación por parte del atacante. Para instalaciones sencillas, Istiod normalmente sólo es alcanzable desde dentro del clúster, limitando el radio de explosión. Sin embargo, para algunos despliegues, especialmente las topologías de istiod externas, este puerto está expuesto a través de la Internet pública. Las versiones 1.15.2, 1.14.5 y 1.13.9 contienen parches para este problema. no se presentan mitigaciones efectivas, más allá de la actualización. Este bug es debido a un error en el archivo "regexp.Compile" en Go
An uncontrolled resource consumption flaw was found in the Istio control plane, istiod. This issue could allow an unauthenticated remote attacker to send a specially crafted or oversized message that could cause a denial of service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-02 CVE Reserved
- 2022-10-13 CVE Published
- 2024-06-03 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/istio/istio/security/advisories/GHSA-86vr-4wcv-mm9w | Third Party Advisory | |
https://istio.io/latest/news/releases/1.13.x/announcing-1.13.9 | Third Party Advisory | |
https://istio.io/latest/news/releases/1.15.x/announcing-1.15.2 | Third Party Advisory | |
https://istio.io/news/releases/1.14.x/announcing-1.14.5 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-39278 | 2023-01-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2148199 | 2023-01-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Istio Search vendor "Istio" | Istio Search vendor "Istio" for product "Istio" | < 1.13.9 Search vendor "Istio" for product "Istio" and version " < 1.13.9" | - |
Affected
| ||||||
Istio Search vendor "Istio" | Istio Search vendor "Istio" for product "Istio" | >= 1.14.0 < 1.14.5 Search vendor "Istio" for product "Istio" and version " >= 1.14.0 < 1.14.5" | - |
Affected
| ||||||
Istio Search vendor "Istio" | Istio Search vendor "Istio" for product "Istio" | >= 1.15.0 < 1.15.2 Search vendor "Istio" for product "Istio" and version " >= 1.15.0 < 1.15.2" | - |
Affected
|