Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Istio 授权问题漏洞
Vulnerability Description
Istio是一套连接、管理和保护微服务的开放平台。 Istio 1.2.10及之前版本、1.3至1.3.7版本和1.4至1.4.3版本中身份验证策略的精准匹配逻辑存在授权问题漏洞。攻击者可利用该漏洞绕过身份验证,访问HTTP路径。
CVSS Information
N/A
Vulnerability Type
N/A