Database/Container, Kubernetes & orchestration
Istio: Gateway/DestinationRule credentialName can read TLS secrets from other namespaces
CVSS 8.8CVE-2021-34824Container, Kubernetes & orchestrationcurated
Impact
Gateway/DestinationRule credentialName can read TLS secrets from other namespaces; cross-tenant private key theft
Who can reach it
Cluster user with namespace access who can create Gateways
What to do
Rolling istiod upgrade; rotate all mesh TLS keys
References
Related entries
- Istio: When JWKS resolution fails, istiod falls back to hardcoded defaults, weakening JWT validationCVE-2026-31837 · IstioHigh
- Istio: Case-sensitivity mismatch in host matching bypasses authorization policyCVE-2021-39155 · IstioHigh
- Istio: Host header with a port bypasses AuthorizationPolicy host matchingCVE-2021-39156 · IstioHigh
- Istio: Localhost access to the istiod pod lets a user impersonate any workload identity in the meshCVE-2022-39388 · IstioHigh
- Istio: Crafted message crashes istiodCVE-2022-23635 · IstioHigh
- Istio: Crafted message DoSes istiodCVE-2022-39278 · IstioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.