GPU VulnDB

Database/Container, Kubernetes & orchestration

Istio: Gateway/DestinationRule credentialName can read TLS secrets from other namespaces

CVE-2021-34824Container, Kubernetes & orchestrationcurated

Impact

Gateway/DestinationRule credentialName can read TLS secrets from other namespaces; cross-tenant private key theft

Who can reach it

Cluster user with namespace access who can create Gateways

What to do

Rolling istiod upgrade; rotate all mesh TLS keys

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.