
Cloud Vulnerability DB
A community-led vulnerabilities database
A remotely exploitable vulnerability was discovered in Istio versions before 1.8.6 and 1.9.x before 1.9.5, identified as CVE-2021-31921. The vulnerability allows external clients to access unexpected services in the cluster and bypass authorization checks when a gateway is configured with AUTO_PASSTHROUGH routing configuration. This security issue was disclosed on May 11, 2021, and primarily affects multi-network multi-cluster deployments (Istio Security).
The vulnerability received a CVSS Impact Score of 10.0 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The issue specifically impacts deployments using the AUTO_PASSTHROUGH Gateway type, which is typically utilized in multi-network multi-cluster configurations. The vulnerability allows unauthorized access to cluster services by bypassing the intended authorization mechanisms (Istio Security).
When exploited, this vulnerability enables external clients to access services within the cluster that should be restricted, effectively bypassing security controls. The critical CVSS score of 10.0 indicates the potential for complete compromise of system confidentiality, integrity, and availability (Istio Security).
The vulnerability is remotely exploitable and requires no special privileges or user interaction to exploit. It specifically affects configurations using AUTO_PASSTHROUGH Gateway type in multi-network multi-cluster deployments (Istio Security).
Users are advised to update their clusters to the latest supported versions: Istio 1.8.6 for 1.8.x users, or Istio 1.9.5 or higher for 1.9.x users. Administrators can check if they are impacted by running a kubectl command to detect AUTO_PASSTHROUGH Gateways in their cluster (Istio Security, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."