Bug 1996929 (CVE-2021-39155) - CVE-2021-39155 istio/istio: HTTP request can bypass authorization mechanisms due to case insensitive host comparison
Summary: CVE-2021-39155 istio/istio: HTTP request can bypass authorization mechanisms ...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-39155
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: Embargoed1996912
TreeView+ depends on / blocked
 
Reported: 2021-08-24 03:04 UTC by Mark Cooper
Modified: 2021-08-25 15:34 UTC (History)
3 users (show)

Fixed In Version: istio 1.11.1, istio 1.10.4, istio 1.9.8
Doc Type: If docs needed, set a value
Doc Text:
An authorization bypass vulnerability was found in istio/istio. The case insensitive host comparison incorrectly works when evaluating rules specified with `host` or `notHost`. This flaw allows an attacker to bypass an Istio authorization policy that uses hosts in the rules, potentially gaining access to the downstream services. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Clone Of:
Environment:
Last Closed: 2021-08-25 15:34:58 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2021:3272 0 None None None 2021-08-25 09:35:29 UTC
Red Hat Product Errata RHSA-2021:3273 0 None None None 2021-08-25 09:34:42 UTC

Description Mark Cooper 2021-08-24 03:04:30 UTC
Istio through 1.11.0 contains a vulnerability where the authorization mechanism can be bypassed when using rules that specify `host` or `notHost` due to a case insensitive host comparison.

Comment 2 errata-xmlrpc 2021-08-25 09:34:41 UTC
This issue has been addressed in the following products:

  OpenShift Service Mesh 1.1

Via RHSA-2021:3273 https://access.redhat.com/errata/RHSA-2021:3273

Comment 3 errata-xmlrpc 2021-08-25 09:35:27 UTC
This issue has been addressed in the following products:

  OpenShift Service Mesh 2.0

Via RHSA-2021:3272 https://access.redhat.com/errata/RHSA-2021:3272

Comment 4 Product Security DevOps Team 2021-08-25 15:34:58 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-39155


Note You need to log in before you can comment on or make changes to this bug.