CVE-2020-16844: Improper Authentication
(updated )
In Istio, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g.
, *-some-suffix
) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.
References
Detect and mitigate CVE-2020-16844 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →