CVE-2020-16844: Authorization bypass in Istio
(updated )
In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.
References
- github.com/advisories/GHSA-82mm-ffjr-h86c
- github.com/istio/istio/commit/4c73414556b83f0e75c1b3a0a89a23103a71573c
- github.com/istio/istio/commit/72d2e135374f421b656d6f1a21f474db46134ace
- github.com/istio/istio/releases
- github.com/istio/istio/releases/tag/1.5.9
- github.com/istio/istio/releases/tag/1.6.8
- istio.io/latest/news/releases/1.5.x/announcing-1.5.9/
- istio.io/latest/news/releases/1.6.x/announcing-1.6.8/
- istio.io/latest/news/security/istio-security-2020-009/
- nvd.nist.gov/vuln/detail/CVE-2020-16844
Detect and mitigate CVE-2020-16844 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →