CVE-2019-12243Improper Access Control in Istio

Severity
7.5HIGHNVD
EPSS
0.1%
top 68.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 5
Latest updateFeb 15

Description

Istio 1.1.x through 1.1.6 has Incorrect Access Control.

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

Goistio.io/istio1.1.01.1.7
NVDistio/istio1.11.1.6

🔴Vulnerability Details

2
OSV
Istio may not check inbound TCP connections against istio-policy2022-02-15
GHSA
Istio may not check inbound TCP connections against istio-policy2022-02-15
CVE-2019-12243 — Improper Access Control in Istio | cvebase