MEDIUM6.8
GHSA-82mm-ffjr-h86c
Authorization bypass in Istio
Quick fix
GHSA-82mm-ffjr-h86c — istio.io/istio: upgrade to the fixed version with the command below.
go get istio.io/istio@v1.5.9Details
In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.
### Specific Go Packages Affected istio.io/istio/pilot/pkg/security/authz/model/matcher
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-16844[ADVISORY]
- https://github.com/istio/istio/commit/4c73414556b83f0e75c1b3a0a89a23103a71573c[WEB]
- https://github.com/istio/istio/commit/72d2e135374f421b656d6f1a21f474db46134ace[WEB]
- https://github.com/istio/istio/releases[WEB]
- https://github.com/istio/istio/releases/tag/1.5.9[WEB]
- https://github.com/istio/istio/releases/tag/1.6.8[WEB]
- https://istio.io/latest/news/releases/1.5.x/announcing-1.5.9[WEB]
- https://istio.io/latest/news/releases/1.6.x/announcing-1.6.8[WEB]
- https://istio.io/latest/news/security/istio-security-2020-009[WEB]