Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is related to a jwt_authenticator.cc segmentation fault.
References
Link Resource
https://github.com/istio/istio.io/pull/4555 Third Party Advisory
https://github.com/istio/istio/issues/15084 Third Party Advisory
https://istio.io/about/notes/ Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-06-28T09:55:48

Updated: 2019-06-28T09:55:48

Reserved: 2019-06-28T00:00:00


Link: CVE-2019-12995

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-06-28T10:15:11.487

Modified: 2020-08-24T17:37:01.140


Link: CVE-2019-12995

JSON object: View

cve-icon Redhat Information

No data.

CWE