istio: unauthorised access to JWT protected HTTP path
Published Feb 12, 2020
7.3
HIGHCVSS 3.1
EPSS 2.61%
Description
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.
Affected products
No data.
Configuration 1
Configuration 2
- 1.0
Running on/with
- 8.0
No data.
OpenShift Service Mesh 1.0
servicemesh-proxy-0:1.0.7-1.el8
Fixed · RHSA-2020:0477
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1.0 | servicemesh-proxy-0:1.0.7-1.el8 | Fixed | RHSA-2020:0477 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Depending on the paths used in the exact match clause, it is possible to update the path to a regex. As provided by the Istio Product Committee, the following mitigation can be employed. The original policy specifying a JWT protected path is as follows: --- apiVersion: "authentication.istio.io/v1alpha1" kind: "Policy" metadata: name: "jwt-example" namespace: istio-system spec: targets: - name: istio-ingressgateway origins: - jwt: issuer: "testing@secure.istio.io" jwksUri: "https://raw.githubusercontent.com/istio/istio/release-1.4/security/tools/jwt/samples/jwks.json" trigger_rules: - included_paths: - exact: /productpage The exact path definition can then be updated to a regular expression: --- - jwt: issuer: "testing@secure.istio.io" jwksUri: "https://raw.githubusercontent.com/istio/istio/release-1.4/security/tools/jwt/samples/jwks.json" trigger_rules: - included_paths: - regex: '/productpage(\?.*)?' - regex: '/productpage(#.*)?'
References (11)
- https://access.redhat.com/errata/RHSA-2020:0477 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-8595 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2020-8595 x_refsource_CONFIRMMitigationThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1798247 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-8595 x_refsource_MISCIssue TrackingMitigationThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29443 Advisory
- https://github.com/istio/istio/commits/master x_refsource_MISCPatch
- https://istio.io/news/security/ x_refsource_MISCVendor Advisory
- https://istio.io/news/security/istio-security-2020-001/ x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8595
- https://www.cve.org/CVERecord?id=CVE-2020-8595
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2020:0477 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2020-8595 | Vendor Advisory | |
| https://access.redhat.com/security/cve/cve-2020-8595 | x_refsource_CONFIRMMitigationThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1798247 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-8595 | x_refsource_MISCIssue TrackingMitigationThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29443 | Advisory | |
| https://github.com/istio/istio/commits/master | x_refsource_MISCPatch | |
| https://istio.io/news/security/ | x_refsource_MISCVendor Advisory | |
| https://istio.io/news/security/istio-security-2020-001/ | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8595 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-8595 |
Change history (0)
No recorded changes yet.