CVE Vulnerabilities

CVE-2021-34824

Published: Jun 29, 2021 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
9.1 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

Affected Software

NameVendorStart VersionEnd Version
IstioIstio1.8.0 (including)1.9.6 (excluding)
IstioIstio1.10.0 (including)1.10.2 (excluding)

References