HIGH7.5
GHSA-vc7h-cmp3-4hw5
Istio vulnerable to denial of service
Quick fix
GHSA-vc7h-cmp3-4hw5 — istio.io/istio: upgrade to the fixed version with the command below.
go get istio.io/istio@v1.3.5Details
Istio 1.3.x before 1.3.5 is vulnerable to denial of service because `continue_on_listener_filters_timeout` is set to True, a related issue to CVE-2019-18836.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-18817[ADVISORY]
- https://github.com/istio/istio/issues/18229[WEB]
- https://github.com/istio/istio/issues/18229#issuecomment-553190142[WEB]
- https://github.com/istio/istio/commit/7570a1f5b56c108aed6ecfa5d2a6048f444bfb37[WEB]
- https://github.com/istio/istio[PACKAGE]
- https://istio.io/news/2019/announcing-1.3.5[WEB]