CVE-2021-31920

Related Vulnerabilities: CVE-2021-31920  

An authorization bypass flaw was found in Istio. This flaw allows an attacker to craft an HTTP request that defines a certain pattern of escaped characters in the URI path (such as %2F, %2f, %5C, or %5c), allowing them to bypass the authorization service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Description

An authorization bypass flaw was found in Istio. This flaw allows an attacker to craft an HTTP request that defines a certain pattern of escaped characters in the URI path (such as %2F, %2f, %5C, or %5c), allowing them to bypass the authorization service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Statement

This CVE addresses the specific fixes required in istio to support the vulnerability found in envoyproxy/envoy, CVE-2021-29492.

This CVE addresses the specific fixes required in istio to support the vulnerability found in envoyproxy/envoy, CVE-2021-29492.

Additional Information

  • Bugzilla 1959481: CVE-2021-31920 istio/istio: HTTP request with escaped slash characters can bypass authorization mechanisms
  • CWE-863: Incorrect Authorization
  • FAQ: Frequently asked questions about CVE-2021-31920