Database/Container, Kubernetes & orchestration
Istio: Localhost access to the istiod pod lets a user impersonate any workload identity in the mesh
CVSS 7.6CVE-2022-39388Container, Kubernetes & orchestrationcurated
Impact
Localhost access to the istiod pod lets a user impersonate any workload identity in the mesh
Who can reach it
An attacker with a foothold in the istiod pod
What to do
Rolling istiod upgrade; restrict exec into istio-system
References
Related entries
- Istio: Crafted message crashes istiodCVE-2022-23635 · IstioHigh
- Istio: Crafted message DoSes istiodCVE-2022-39278 · IstioHigh
- Istio: Authentication Policy exact-path matching allows unauthorized access to HTTP pathsCVE-2020-8595 · IstioHigh
- Istio: Envoy RBAC header matching flaw bypasses header-based authorization policyCVE-2026-31838 · IstioMedium
- Istio: DENY AuthorizationPolicy with wildcard-suffix principals silently fails to denyCVE-2020-16844 · IstioMedium
- Istio: Multiple or escaped slashes bypass an Istio authorization policyCVE-2021-31920 · IstioMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.