VDB

CVE-2019-14993

CVE-2019-14993 PUBLISHED

Reported by mitre · Published August 13, 2019

Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.

Affected Products

VendorProductVersions
n/an/an/a
wolfiistio-pilot-agent-1.22*, *, *
chainguardistio-pilot-agent-1.22*, *, *
n/an/an/a, *
chainguardistio-operator-1.200, 0, 0
wolfiistio-pilot-agent-1.210, 0, 0
chainguardistio-cni-1.210, 0, 0
chainguardistio-operator-1.22*, *, *
wolfiistio-operator-1.22*, *, *
chainguardistio-pilot-discovery-1.22*, *, *
wolfiistio-pilot-discovery-1.210, 0, 0
wolfiistio-operator-1.210, 0, 0
wolficert-manager-istio-csr*, *, *
chainguardcert-manager-istio-csr-fips*, *, *
wolfiistio-cni-1.22*, *, *
chainguardcert-manager-istio-csr*, *, *
chainguardistio-operator-1.210, 0, 0
chainguardistio-pilot-agent-1.210, 0, 0
istio.ioistio0, 1.2.0, 0
wolfiistio-pilot-discovery-1.22*, *, *

…and 5 more

Timeline

  • Aug 13, 2019 CVE Published
  • Aug 16, 2019 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›