CVE-2020-8843
Istio Control Plane (istiod) vulnerability analysis and mitigation

Overview

CVE-2020-8843 is a vulnerability discovered in Istio-proxy that affects versions 1.3 to 1.3.6. The vulnerability was disclosed on February 11, 2020, and involves the acceptance of x-istio-attributes header at ingress that can be used to affect policy decisions when Mixer policy selectively applies to source equal to ingress (Istio Security).

Technical details

The vulnerability occurs when Istio-proxy improperly accepts the x-istio-attributes header at ingress, which can potentially be used to influence policy decisions specifically when Mixer policy is configured to selectively apply to sources equal to ingress. This feature was disabled by default in Istio 1.3 and 1.4. The vulnerability has been assigned a CVSS v3.1 score of 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) indicating a high severity (Istio Security).

Impact

When exploited, this vulnerability allows attackers to bypass specifically configured Mixer policies. This could potentially lead to unauthorized access or policy decision manipulation in affected Istio deployments where Mixer Policy is enabled and used in the specified way (Istio Security).

Mitigation and workarounds

For Istio 1.3.x deployments, users are advised to update to Istio 1.3.7 or later versions to mitigate this vulnerability. The issue was silently fixed in Istio 1.4.0 and Istio 1.3.7, though it was initially addressed as a non-security issue and later reclassified as a vulnerability in December 2019 (Istio Security).

Community reactions

The vulnerability was initially discovered and privately reported by Krishnan Anantheswaran and Eric Zhang of Splunk, demonstrating responsible disclosure practices in the security community (Istio Security).

Additional resources


SourceThis report was generated using AI

Related Istio Control Plane (istiod) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-31045CRITICAL9.8
  • etcdetcd
  • olcnectl
NoYesJun 09, 2022
CVE-2022-39278HIGH7.5
  • Istio Control Plane (istiod)Istio Control Plane (istiod)
  • olcne-nginx
NoYesOct 13, 2022
CVE-2022-24726HIGH7.5
  • Istio Control Plane (istiod)Istio Control Plane (istiod)
  • istio
NoYesMar 10, 2022
CVE-2022-23635HIGH7.5
  • Istio Control Plane (istiod)Istio Control Plane (istiod)
  • istio-pilot-discovery-1.21
NoYesFeb 22, 2022
CVE-2022-39388LOW3.5
  • Istio Control Plane (istiod)Istio Control Plane (istiod)
  • github.com/istio/istio
NoYesNov 10, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management