Improper Authorization in Istio - CVE-2021-31921
Published: May 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization procedure.
The vulnerability exists due to a logic issue when the istio gateway is configured with TLS mode `AUTO_PASSTHROUGH`. A remote non-authenticated attacker can bypass authorization checks and gain unauthorized access to services in the cluster.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
Affected software
servicemesh (Red Hat package)
OpenShift Service Mesh
How to mitigate CVE-2021-31921
servicemesh (Red Hat package) - addressed in versions 1.1.15-4.el8, 2.0.5-3.el8
OpenShift Service Mesh - update to 2.0.5