Hide Forgot
Istio through 1.9.5 contains a remotely exploitable vulnerability where an HTTP request with escaped slash characters can bypass authorization mechanisms. A subset of this security issue was addressed in the Envoy proxy, CVE-2021-29492.
Statement: This CVE addresses the specific fixes required in istio to support the vulnerability found in envoyproxy/envoy, CVE-2021-29492.
This issue has been addressed in the following products: OpenShift Service Mesh 2.0 Via RHSA-2021:1538 https://access.redhat.com/errata/RHSA-2021:1538
This issue has been addressed in the following products: OpenShift Service Mesh 1.1 Via RHSA-2021:1540 https://access.redhat.com/errata/RHSA-2021:1540
External References: https://istio.io/latest/news/security/istio-security-2021-005/
Acknowledgments: Name: the Istio Product Security Working Group
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-31920
*** EmbargoedBug 1921525 has been marked as a duplicate of this bug. ***