VDB

CVE-2020-8595

CVE-2020-8595 PUBLISHED CVSS 7.300000190734863 HIGH

Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.

EPSS 2.61% · 83.9th percentile

Risk Scores

CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
2.61%
83.9th percentile

Affected Products

VendorProductVersions
istioistio1.3, 1.4.0
n/an/an/a
redhatopenshift_service_mesh1.0

Timeline

  • Feb 12, 2020 CVE Published
  • Feb 20, 2020 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Jun 4, 2021 EPSS Score
  • Jul 22, 2021 EPSS Score
  • Sep 5, 2021 EPSS Score
  • Dec 6, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 21, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 7, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›