Skip to content

Identity impersonation if user has localhost access

High
howardjohn published GHSA-6c6p-h79f-g6p4 Nov 9, 2022

Package

Istio

Affected versions

1.15.2

Patched versions

1.15.3

Description

Impact

User can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane.

Patches

1.15.3

Workarounds

No. If using 1.15.2 please upgrade to 1.15.3 or later.

References

None at this time.

For more information

If you have any questions or comments about this advisory, please email us at istio-security-vulnerability-reports@googlegroups.com

Severity

High
7.6
/ 10

CVSS base metrics

Attack vector
Adjacent
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

CVE ID

CVE-2022-39388

Weaknesses

No CWEs

Credits