8.8
CVSSv3

CVE-2020-14306

Published: 16/09/2020 Updated: 07/11/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions up to and including 1.1.3. This flaw allows an attacker with a basic level of access to the cluster to deploy a custom gateway/pod to any namespace, potentially gaining access to privileged service account tokens. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

istio-operator project istio-operator

Vendor Advisories

Synopsis Important: Red Hat OpenShift Service Mesh 11 servicemesh-operator security update Type/Severity Security Advisory: Important Topic An update for servicemesh-operator is now available for OpenShift Service Mesh 11Red Hat Product Security has rated this update as having a security impact of Import ...