Information Exposure Affecting istio.io/istio/pilot/pkg/xds package, versions >=1.10.0 <1.10.2>=1.8.0 <1.9.6


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Not Defined
EPSS
0.1% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-ISTIOIOISTIOPILOTPKGXDS-1315150
  • published30 Jun 2021
  • disclosed30 Jun 2021
  • creditNishant Virmani, Stephane Mercier, Antonin Nycz, John Howard

Introduced: 30 Jun 2021

CVE-2021-34824  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade istio.io/istio/pilot/pkg/xds to version 1.10.2, 1.9.6 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure. Credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

Users are only impacted if ALL of following conditions are true for their clusters:

  • It is using a vulnerable version of Istio.
  • It has defined Gateways or DestinationRules with the credentialName field specified.
  • It does not specify the Istiod flag PILOT_ENABLE_XDS_CACHE=false.

CVSS Scores

version 3.1