
Cloud Vulnerability DB
A community-led vulnerabilities database
Istio, an open platform for connecting, managing, and securing microservices, disclosed a vulnerability (CVE-2022-39388) affecting versions on the 1.15.x branch prior to 1.15.3. The vulnerability allows a user with localhost access to the Istiod control plane to impersonate any workload identity within the service mesh (Istio Advisory). The issue was patched in version 1.15.3, released on October 27, 2022 (Istio Release).
The vulnerability is related to incorrect authorization (CWE-863) in the XFCC (X-Forwarded-Client-Cert) authenticator component. The CVSS v3.1 base score is 7.6 (High), with the following vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N. This indicates adjacent network attack vector, low attack complexity, low privileges required, no user interaction needed, changed scope, high confidentiality impact, low integrity impact, and no availability impact (NVD).
The vulnerability allows an attacker with localhost access to the Istiod control plane to impersonate any workload identity within the service mesh. This could lead to unauthorized access and potential security breaches within the service mesh environment (Istio Advisory).
The vulnerability requires the attacker to have localhost access to the Istiod control plane. The attack complexity is considered low, and no user interaction is needed for exploitation. The attacker needs low privileges to execute the attack (NVD).
There are no known workarounds for this vulnerability. Users running affected versions (1.15.x branch prior to 1.15.3) should upgrade to version 1.15.3 or later to address this security issue (Istio Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."