VDB
Sign up
HIGH7.5

GHSA-qcvw-82hh-gq38

Istio ReDoS Vulnerability

Quick fix

GHSA-qcvw-82hh-gq38 — istio.io/istio: upgrade to the fixed version with the command below.

go get istio.io/istio@v1.1.13

Details

Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/istio.io/istio
Introduced in: 0Fixed in: 1.1.13
Fixgo get istio.io/istio@v1.1.13
Go/istio.io/istio
Introduced in: 1.2.0Fixed in: 1.2.4
Fixgo get istio.io/istio@v1.2.4

References