PT-2024-39308 · Amazon+1 · Aws Alb Route Directive Adapter For Istio+1
Liad-Miggo
·
Published
2024-10-21
·
Updated
2025-10-14
·
CVE-2024-8901
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
AWS ALB Route Directive Adapter For Istio (affected versions not specified)
Description:
The issue concerns a lack of proper signer and issuer validation in the JWT authentication mechanism used by the AWS ALB Route Directive Adapter For Istio. This allows an actor to provide a JWT signed by an untrusted entity, potentially spoofing OIDC-federated sessions and bypassing authentication in deployments where ALB targets are directly exposed to internet traffic. The repository has been deprecated and is no longer supported. As a security best practice, it is recommended to ensure ELB targets do not have public IP addresses.
Recommendations:
As a temporary workaround, consider validating that the signer attribute in the JWT matches the ARN of the Application Load Balancer that the service is configured to use.
Ensure any forked or derivative code implements proper signer and issuer validation for JWT authentication.
Restrict access to ELB targets, such as EC2 Instances or Fargate Tasks, to minimize the risk of exploitation by not assigning them public IP addresses.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws Alb Route Directive Adapter For Istio
Suse