Vulnerability Description
Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Istio | Istio | >= 1.8.0, < 1.9.6 |
References
- https://github.com/istio/istio/releasesRelease NotesThird Party Advisory
- https://istio.io/latest/news/security/istio-security-2021-007Vendor Advisory
- https://github.com/istio/istio/releasesRelease NotesThird Party Advisory
- https://istio.io/latest/news/security/istio-security-2021-007Vendor Advisory
FAQ
What is CVE-2021-34824?
CVE-2021-34824 is a vulnerability with a CVSS score of 8.8 (HIGH). Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from diff...
How severe is CVE-2021-34824?
CVE-2021-34824 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-34824?
Check the references section above for vendor advisories and patch information. Affected products include: Istio Istio.