VDB
Sign up
HIGH7.5

GHSA-vc7h-cmp3-4hw5

Istio vulnerable to denial of service

Quick fix

GHSA-vc7h-cmp3-4hw5 — istio.io/istio: upgrade to the fixed version with the command below.

go get istio.io/istio@v1.3.5

Details

Istio 1.3.x before 1.3.5 is vulnerable to denial of service because `continue_on_listener_filters_timeout` is set to True, a related issue to CVE-2019-18836.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/istio.io/istio
Introduced in: 1.3.0Fixed in: 1.3.5
Fixgo get istio.io/istio@v1.3.5

References