CVE-2020-8595 Critical Information Severity: Important CVSS v3 Score: 7.3 Published Date: February 11, 2020 Last Modified: October 8, 2025 Vulnerability Description An unauthorized access vulnerability was found in Istio in the servicemesh-proxy. An attacker can specify an HTTP path and gain unauthorized access, even if the path is configured to be accessed with a valid JSON Web Token (JWT). Mitigation Depending on the paths used in the exact match clause, update the path to a regex. Affected Packages Product/Service: OpenShift Service Mesh 1.0 Component: servicemesh-proxy State: Fixed Errata: RHSA-2020:0477 Release Date: February 12, 2020 CVSS v3 Score Breakdown Weakness (CWE) CWE-285: Improper Authorization Acknowledgements Red Hat thanks The Istio Product Security Committee for reporting this issue.