cbcvebase.
CVE-2021-39156
published 2021-08-24

CVE-2021-39156: Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.10%
61.6th percentile
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploitable vulnerability where an HTTP request with `#fragment` in the path may bypass Istio’s URI path based authorization policies. Patches are available in Istio 1.11.1, Istio 1.10.4 and Istio 1.9.8. As a work around a Lua filter may be written to normalize the path.

Affected

8 ranges
VendorProductVersion rangeFixed in
istio.ioistio>= 0 < 1.9.81.9.8
istio.ioistio>= 1.10.0 < 1.10.41.10.4
istio.ioistio>= 1.11.0 < 1.11.11.11.1
istioistio< 1.9.81.9.8
istioistio
istioistio
istioistio>= 1.10.0 < 1.10.31.10.3
istioistio>= 1.11.0 < 1.11.11.11.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.