VDB
CVE-2020-8595
CVE-2020-8595
PUBLISHED
CVSS 7.300000190734863 HIGH
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.
EPSS 2.61% · 83.9th percentile
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
2.61%
83.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| istio | istio | 1.3, 1.4.0 |
| n/a | n/a | n/a |
| redhat | openshift_service_mesh | 1.0 |
Timeline
- Feb 12, 2020 CVE Published
- Feb 20, 2020 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 4, 2021 EPSS Score
- Jul 22, 2021 EPSS Score
- Sep 5, 2021 EPSS Score
- Dec 6, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 21, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 7, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
References
- https://github.com/istio/istio/commits/master url
- https://istio.io/news/security/ url
- RHSA-2020:0477 vendor-advisory
- https://access.redhat.com/security/cve/cve-2020-8595 url
- https://istio.io/news/security/istio-security-2020-001/ url
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-8595 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-8595 advisory
- https://istio.io/news/security url
- https://istio.io/news/security/istio-security-2020-001 url