GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: JWT with an issuer absent from the provider list bypasses JWT authentication

CVSS 8.2CVE-2021-21378Container, Kubernetes & orchestrationcurated

Impact

JWT with an issuer absent from the provider list bypasses JWT authentication

Who can reach it

Unauthenticated network

What to do

Upgrade Envoy

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.