You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue. There are no known workarounds.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/istio/istio/security
packages:
- package: istio
description: |
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue. There are no known workarounds.
cves:
- CVE-2022-39388
references:
- web: https://github.com/istio/istio/security/advisories/GHSA-6c6p-h79f-g6p4
- fix: https://github.com/istio/istio/commit/346260e5115e9fbc65ba8a559bc686e6ca046a32
- fix: https://github.com/istio/istio/commit/9a643e270421560afb2630e00f76d46a55499df9
- web: https://istio.io/latest/news/releases/1.15.x/announcing-1.15.3/
The text was updated successfully, but these errors were encountered:
CVE-2022-39388 references github.com/istio/istio/security, which may be a Go module.
Description:
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue. There are no known workarounds.
References:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: