Vulnerabilities > Istio > Istio > 1.8.3

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
2022-10-13 CVE-2022-39278 Resource Exhaustion vulnerability in Istio
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection.
network
low complexity
istio CWE-400
7.5
2022-06-09 CVE-2022-31045 Out-of-bounds Read vulnerability in Istio
Istio is an open platform to connect, manage, and secure microservices.
network
low complexity
istio CWE-125
7.5
2022-03-10 CVE-2022-24726 Resource Exhaustion vulnerability in Istio
Istio is an open platform to connect, manage, and secure microservices.
network
low complexity
istio CWE-400
5.0
2022-02-22 CVE-2022-23635 Improper Validation of Specified Quantity in Input vulnerability in Istio
Istio is an open platform to connect, manage, and secure microservices.
network
low complexity
istio CWE-1284
7.5
2021-08-24 CVE-2021-39155 Incorrect Authorization vulnerability in Istio
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data.
network
low complexity
istio CWE-863
7.5
2021-08-24 CVE-2021-39156 Use of Incorrectly-Resolved Name or Reference vulnerability in Istio
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data.
network
low complexity
istio CWE-706
7.5
2021-06-29 CVE-2021-34824 Unspecified vulnerability in Istio
Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.
network
low complexity
istio
6.5
2021-06-02 CVE-2021-31921 Missing Authorization vulnerability in Istio
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration.
network
istio CWE-862
6.8
2021-05-27 CVE-2021-31920 Use of Incorrectly-Resolved Name or Reference vulnerability in Istio
Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorization rules are used.
network
low complexity
istio CWE-706
4.0