Vulnerabilities > Istio > High

DATE CVE VULNERABILITY TITLE RISK
2020-02-12 CVE-2020-8595 Improper Authentication vulnerability in multiple products
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass.
network
low complexity
istio redhat CWE-287
7.3
2019-11-12 CVE-2019-18817 Infinite Loop vulnerability in Istio
Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related issue to CVE-2019-18836.
network
low complexity
istio CWE-835
7.5
2019-11-11 CVE-2019-18836 Infinite Loop vulnerability in multiple products
Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used."
network
low complexity
envoyproxy istio CWE-835
7.5
2019-08-13 CVE-2019-14993 Incorrect Regular Expression vulnerability in Istio
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.
network
low complexity
istio CWE-185
7.5
2019-06-28 CVE-2019-12995 NULL Pointer Dereference vulnerability in Istio
Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy.
network
low complexity
istio CWE-476
7.5
2019-06-05 CVE-2019-12243 Unspecified vulnerability in Istio
Istio 1.1.x through 1.1.6 has Incorrect Access Control.
high complexity
istio
7.5