istio/envoy: mishandling regular expressions for long URIs leading to DoS
Published Aug 13, 2019
7.5
HIGHCVSS 3.0
EPSS 2.29%
Description
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.
Affected products
No data.
No data.
OpenShift Service Mesh 1.1
ior-0:1.1.0-3.el8
Fixed · RHEA-2020:1416
OpenShift Service Mesh 1.1
servicemesh-0:1.1.0-5.el8
Fixed · RHEA-2020:1416
OpenShift Service Mesh 1.1
servicemesh-cni-0:1.1.0-3.el8
Fixed · RHEA-2020:1416
OpenShift Service Mesh 1.1
servicemesh-grafana-0:6.4.3-2.el8
Fixed · RHEA-2020:1416
OpenShift Service Mesh 1.1
servicemesh-operator-0:1.1.0-9.el8
Fixed · RHEA-2020:1416
OpenShift Service Mesh 1.1
servicemesh-prometheus-0:2.14.0-3.el8
Fixed · RHEA-2020:1416
OpenShift Service Mesh 1.1
servicemesh-proxy-0:1.1.0-4.el8
Fixed · RHEA-2020:1416
Openshift Service Mesh 1.1
kiali-0:v1.12.7.redhat1-1.el7
Fixed · RHEA-2020:1416
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1.1 | ior-0:1.1.0-3.el8 | Fixed | RHEA-2020:1416 |
| OpenShift Service Mesh 1.1 | servicemesh-0:1.1.0-5.el8 | Fixed | RHEA-2020:1416 |
| OpenShift Service Mesh 1.1 | servicemesh-cni-0:1.1.0-3.el8 | Fixed | RHEA-2020:1416 |
| OpenShift Service Mesh 1.1 | servicemesh-grafana-0:6.4.3-2.el8 | Fixed | RHEA-2020:1416 |
| OpenShift Service Mesh 1.1 | servicemesh-operator-0:1.1.0-9.el8 | Fixed | RHEA-2020:1416 |
| OpenShift Service Mesh 1.1 | servicemesh-prometheus-0:2.14.0-3.el8 | Fixed | RHEA-2020:1416 |
| OpenShift Service Mesh 1.1 | servicemesh-proxy-0:1.1.0-4.el8 | Fixed | RHEA-2020:1416 |
| Openshift Service Mesh 1.1 | kiali-0:v1.12.7.redhat1-1.el7 | Fixed | RHEA-2020:1416 |
istio.io/istio
Go
Introduced 0 Fixed 1.1.13istio.io/istio
Go
Introduced 1.2.0 Fixed 1.2.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | istio.io/istio | 0 | 1.1.13 |
| Go | istio.io/istio | 1.2.0 | 1.2.4 |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2019-14993 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1759816 Issue Tracking
- https://discuss.istio.io/t/upcoming-security-updates-in-istio-1-2-4-and-1-1-13/3383 x_refsource_MISCVendor Advisory
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=86164 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-qcvw-82hh-gq38 Advisory
- https://github.com/envoyproxy/envoy/issues/7728 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://istio.io/blog/2019/istio-security-003-004/ x_refsource_CONFIRMVendor Advisory
- https://istio.io/news/2019/istio-security-003-004/
- https://nvd.nist.gov/vuln/detail/CVE-2019-14993
- https://www.cve.org/CVERecord?id=CVE-2019-14993
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-14993 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1759816 | Issue Tracking | |
| https://discuss.istio.io/t/upcoming-security-updates-in-istio-1-2-4-and-1-1-13/3383 | x_refsource_MISCVendor Advisory | |
| https://gcc.gnu.org/bugzilla/show_bug.cgi?id=86164 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-qcvw-82hh-gq38 | Advisory | |
| https://github.com/envoyproxy/envoy/issues/7728 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://istio.io/blog/2019/istio-security-003-004/ | x_refsource_CONFIRMVendor Advisory | |
| https://istio.io/news/2019/istio-security-003-004/ | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-14993 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-14993 |
Change history (0)
No recorded changes yet.