Lucene search

K
freebsdFreeBSD484D3F5E-653A-11E9-B0E3-1C39475B9F84
HistoryMar 29, 2019 - 12:00 a.m.

Istio -- Security vulnerabilities

2019-03-2900:00:00
vuxml.freebsd.org
8

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

0.004 Low

EPSS

Percentile

75.1%

Istio reports:

Two security vulnerabilities have recently been identified in the Envoy proxy.
The vulnerabilities are centered on the fact that Envoy did not normalize
HTTP URI paths and did not fully validate HTTP/1.1 header values. These
vulnerabilities impact Istio features that rely on Envoy to enforce any of
authorization, routing, or rate limiting.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchistio< 1.1.2UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

0.004 Low

EPSS

Percentile

75.1%