Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.
References
Link Resource
https://github.com/istio/istio/releases Release Notes Third Party Advisory
https://istio.io/latest/news/security/istio-security-2021-007 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-06-29T13:30:01

Updated: 2021-07-07T14:30:14

Reserved: 2021-06-17T00:00:00


Link: CVE-2021-34824

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-06-29T14:15:08.500

Modified: 2022-07-12T17:42:04.277


Link: CVE-2021-34824

JSON object: View

cve-icon Redhat Information

No data.