CVE-2021-39156

Related Vulnerabilities: CVE-2021-39156  

An authorization bypass vulnerability was found in istio/istio. An HTTP request is incorrectly evaluated when a URI #fragment is specified. This flaw allows an attacker to bypass an Istio URI-based authorization rule. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Description

An authorization bypass vulnerability was found in istio/istio. An HTTP request is incorrectly evaluated when a URI #fragment is specified. This flaw allows an attacker to bypass an Istio URI-based authorization rule. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Additional Information

  • Bugzilla 1996915: CVE-2021-39156 istio/istio: HTTP request with fragment in URI can bypass authorization mechanisms
  • CWE-863: Incorrect Authorization
  • FAQ: Frequently asked questions about CVE-2021-39156