Vulnerability Description
Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorization rules are used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Istio | Istio | < 1.8.6 |
Related Weaknesses (CWE)
References
- https://istio.io/latest/news/security/istio-security-2021-005/ExploitVendor Advisory
- https://istio.io/latest/news/security/istio-security-2021-005/ExploitVendor Advisory
FAQ
What is CVE-2021-31920?
CVE-2021-31920 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an...
How severe is CVE-2021-31920?
CVE-2021-31920 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31920?
Check the references section above for vendor advisories and patch information. Affected products include: Istio Istio.