CVE-2020-16844
Last modified
CVE-2020-16844 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.. EPSS estimates a 1.09% chance of exploitation in the next 30 days.
Description
In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Istio | Istio | >= 1.5.0, <= 1.5.8 |
| Istio | Istio | >= 1.6.0, <= 1.6.7 |
References
- https://github.com/istio/istio/releasesVendor Advisory
- https://istio.io/latest/news/security/istio-security-2020-009/Exploit, Mitigation, Vendor Advisory
- https://github.com/istio/istio/releasesVendor Advisory
- https://istio.io/latest/news/security/istio-security-2020-009/Exploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-16844?
How severe is CVE-2020-16844?
How do I fix CVE-2020-16844?
Are you affected by CVE-2020-16844?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
