Vulnerabilities > Istio > Istio > 1.4.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-10 | CVE-2023-44487 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | 7.5 |
2022-10-13 | CVE-2022-39278 | Unspecified vulnerability in Istio Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. | 7.5 |
2022-06-09 | CVE-2022-31045 | Unspecified vulnerability in Istio Istio is an open platform to connect, manage, and secure microservices. | 9.8 |
2022-03-10 | CVE-2022-24726 | Resource Exhaustion vulnerability in Istio Istio is an open platform to connect, manage, and secure microservices. | 7.5 |
2022-02-22 | CVE-2022-23635 | Improper Validation of Specified Quantity in Input vulnerability in Istio Istio is an open platform to connect, manage, and secure microservices. | 7.5 |
2021-08-24 | CVE-2021-39155 | Incorrect Authorization vulnerability in Istio Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. | 7.5 |
2021-08-24 | CVE-2021-39156 | Use of Incorrectly-Resolved Name or Reference vulnerability in Istio Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. | 7.5 |
2021-06-02 | CVE-2021-31921 | Missing Authorization vulnerability in Istio Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration. | 9.8 |
2021-05-27 | CVE-2021-31920 | Use of Incorrectly-Resolved Name or Reference vulnerability in Istio Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorization rules are used. | 6.5 |
2021-01-29 | CVE-2019-25014 | NULL Pointer Dereference vulnerability in multiple products A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. | 6.5 |