Istio · Istio · CVE-2021-31920
Name of the Vulnerable Software and Affected Versions:
Istio versions 1.8.0 through 1.8.6
Istio versions 1.9.0 through 1.9.5
Description:
The issue allows an HTTP request path with multiple slashes or escaped slash characters (`%2F` or `%5C`) to potentially bypass an authorization policy when path-based authorization rules are used. This could lead to unauthorized access.
Recommendations:
For Istio versions 1.8.0 through 1.8.5, update to version 1.8.6.
For Istio versions 1.9.0 through 1.9.4, update to version 1.9.5.