Related Vulnerabilities: CVE-2021-32777  

Envoy, as used by Istio before version 1.11.1, contains a remotely exploitable vulnerability that an HTTP request with multiple value headers could do an incomplete authorization policy check when the ext_authz extension is used. When a request header contains multiple values, the external authorization server will only see the last value of the given header.

Severity High

Remote Yes

Type Insufficient validation

Description

Envoy, as used by Istio before version 1.11.1, contains a remotely exploitable vulnerability that an HTTP request with multiple value headers could do an incomplete authorization policy check when the ext_authz extension is used. When a request header contains multiple values, the external authorization server will only see the last value of the given header.

AVG-2321 istio 1.11.0-1 High Vulnerable

https://istio.io/latest/news/security/istio-security-2021-008/#cve-2021-32777