6.8
CVSSv3

CVE-2020-16844

Published: 01/10/2020 Updated: 15/10/2020
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.8 | Impact Score: 5.2 | Exploitability Score: 1.6
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 up to and including 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

istio istio

Vendor Advisories

Synopsis Moderate: Red Hat OpenShift Service Mesh 11 security update Type/Severity Security Advisory: Moderate Topic An update for servicemesh is now available for OpenShift Service Mesh 11Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scori ...