Unauthenticated control plane denial of service attack in Istio
Published Feb 22, 2022
7.5
HIGHCVSS 3.1
EPSS 1.66%
Description
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane crashing. This endpoint is served over TLS port 15012, but does not require any authentication from the attacker. For simple installations, Istiod is typically only reachable from within the cluster, limiting the blast radius. However, for some deployments, especially [multicluster](https://istio.io/latest/docs/setup/install/multicluster/primary-remote/) topologies, this port is exposed over the public internet. There are no effective workarounds, beyond upgrading. Limiting network access to Istiod to the minimal set of clients can help lessen the scope of the vulnerability to some extent.
Affected products
-
Affected
- < 1.11.7
- ≥ 1.12.0, < 1.12.4
- ≥ 1.13.0, < 1.13.1
No data.
OpenShift Service Mesh 2.0
servicemesh-0:2.0.9-3.el8
Fixed · RHSA-2022:1276
OpenShift Service Mesh 2.1
servicemesh-0:2.1.2-4.el8
Fixed · RHSA-2022:1275
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 2.0 | servicemesh-0:2.0.9-3.el8 | Fixed | RHSA-2022:1276 |
| OpenShift Service Mesh 2.1 | servicemesh-0:2.1.2-4.el8 | Fixed | RHSA-2022:1275 |
istio.io/istio
Go
Introduced 1.13.0 Fixed 1.13.1istio.io/istio
Go
Introduced 1.12.0 Fixed 1.12.4istio.io/istio
Go
Introduced 0 Fixed 1.11.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | istio.io/istio | 1.13.0 | 1.13.1 |
| Go | istio.io/istio | 1.12.0 | 1.12.4 |
| Go | istio.io/istio | 0 | 1.11.7 |
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-23635 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2057277 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0904 Advisory
- https://github.com/advisories/GHSA-856q-xv3c-7f2f Advisory
- https://github.com/istio/istio/commit/5f3b5ed958ae75156f8656fe7b3794f78e94db84 x_refsource_MISCPatchThird Party Advisory
- https://github.com/istio/istio/security/advisories/GHSA-856q-xv3c-7f2f x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://istio.io/latest/news/security/istio-security-2022-003 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-23635
- https://www.cve.org/CVERecord?id=CVE-2022-23635
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-23635 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2057277 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0904 | Advisory | |
| https://github.com/advisories/GHSA-856q-xv3c-7f2f | Advisory | |
| https://github.com/istio/istio/commit/5f3b5ed958ae75156f8656fe7b3794f78e94db84 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/istio/istio/security/advisories/GHSA-856q-xv3c-7f2f | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://istio.io/latest/news/security/istio-security-2022-003 | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-23635 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-23635 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub