Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended policy.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Istio 安全漏洞
Vulnerability Description
Istio是一套连接、管理和保护微服务的开放平台。 Istio 1.5.8版本和1.6.5版本中存在安全漏洞。攻击者可利用该漏洞破坏特定的DENY规则,从而获得受限资源的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A