Closed
Description
CVE-2020-8595 references github.com/istio/istio, which may be a Go module.
Description:
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.
References:
- NIST: https://nvd.nist.gov/vuln/detail/CVE-2020-8595
- fix: https://github.com/istio/istio/commits/master
- web: https://istio.io/news/security/
- web: https://access.redhat.com/errata/RHSA-2020:0477
- web: https://access.redhat.com/security/cve/cve-2020-8595
- web: https://istio.io/news/security/istio-security-2020-001/
- web: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-8595
- Imported by: https://pkg.go.dev/github.com/istio/istio?tab=importedby
Cross references:
- Module github.com/istio/istio appears in issue x/vulndb: potential Go vuln in github.com/istio/istio/security: CVE-2022-21679 #297 EFFECTIVELY_PRIVATE
- Module github.com/istio/istio appears in issue x/vulndb: potential Go vuln in github.com/istio/istio/security: CVE-2022-21701 #299 EFFECTIVELY_PRIVATE
- Module github.com/istio/istio appears in issue x/vulndb: potential Go vuln in github.com/istio/istio/security: CVE-2022-23635 #338 EFFECTIVELY_PRIVATE
- Module github.com/istio/istio appears in issue x/vulndb: potential Go vuln in github.com/istio/istio/security: CVE-2022-24726 #352 EFFECTIVELY_PRIVATE
- Module github.com/istio/istio appears in issue x/vulndb: potential Go vuln in github.com/istio/istio/security: CVE-2022-31045 #489 EFFECTIVELY_PRIVATE
- Module github.com/istio/istio appears in issue x/vulndb: potential Go vuln in github.com/istio/istio: CVE-2022-39278 #1064 DEPENDENT_VULNERABILITY
- Module github.com/istio/istio appears in issue x/vulndb: potential Go vuln in github.com/istio/istio: GHSA-6c6p-h79f-g6p4 #1101 NOT_IMPORTABLE
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/istio/istio
vulnerable_at: 0.0.0-20231108040633-7df817a6ab40
packages:
- package: n/a
cves:
- CVE-2020-8595
references:
- fix: https://github.com/istio/istio/commits/master
- web: https://istio.io/news/security/
- web: https://access.redhat.com/errata/RHSA-2020:0477
- web: https://access.redhat.com/security/cve/cve-2020-8595
- web: https://istio.io/news/security/istio-security-2020-001/
- web: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-8595