#VU53523 Improper Authorization in Istio - CVE-2021-31921
Published: May 25, 2021
Istio
Istio
Description
The vulnerability allows a remote attacker to bypass authorization procedure.
The vulnerability exists due to a logic issue when the istio gateway is configured with TLS mode `AUTO_PASSTHROUGH`. A remote non-authenticated attacker can bypass authorization checks and gain unauthorized access to services in the cluster.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.