Improper Authorization in Istio - CVE-2021-31921

 

Improper Authorization in Istio - CVE-2021-31921

Published: May 25, 2021


Vulnerability identifier: #VU53523
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-31921
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization procedure.

The vulnerability exists due to a logic issue when the istio gateway is configured with TLS mode `AUTO_PASSTHROUGH`. A remote non-authenticated attacker can bypass authorization checks and gain unauthorized access to services in the cluster.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

Istio
servicemesh (Red Hat package)
OpenShift Service Mesh

How to mitigate CVE-2021-31921

Install updates from vendor's website.

Istio - addressed in versions 1.8.6, 1.9.5
servicemesh (Red Hat package) - addressed in versions 1.1.15-4.el8, 2.0.5-3.el8
OpenShift Service Mesh - update to 2.0.5

External References

Related Security Bulletins