HIGH🇵🇱 Wersja polska

CVE-2022-31045

CVSS 7.0v3.1pub. 2022-06-09upd. 2024-11-21

Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and 1.14.1. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
  • Istio

    APP
    Istio
    1.14.0< 1.12.81.13.0 – 1.13.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-31921CRITICAL9.8PL ✓same product

Istio: ominięcie autoryzacji przy konfiguracji AUTO_PASSTHROUGH

CVE-2026-31837HIGH8.7same product

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a...

CVE-2022-39388HIGH7.6same product

Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior...

CVE-2022-39278HIGH7.5same product

Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and t...

CVE-2022-24726HIGH7.5same product

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control...