CVE-2020-16844

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/10/2020
Last modified:
15/10/2020

Description

In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* 1.5.0 (including) 1.5.8 (including)
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* 1.6.0 (including) 1.6.7 (including)