Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-8595

Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.1%
CVSS Severity
CVSS v3 Score 7.3
CVSS v2 Score 7.5
Products affected by CVE-2020-8595
  • Istio » Istio » Version: 1.3
    cpe:2.3:a:istio:istio:1.3
  • Istio » Istio » Version: 1.3.0
    cpe:2.3:a:istio:istio:1.3.0
  • Istio » Istio » Version: 1.3.1
    cpe:2.3:a:istio:istio:1.3.1
  • Istio » Istio » Version: 1.3.2
    cpe:2.3:a:istio:istio:1.3.2
  • Istio » Istio » Version: 1.3.3
    cpe:2.3:a:istio:istio:1.3.3
  • Istio » Istio » Version: 1.3.4
    cpe:2.3:a:istio:istio:1.3.4
  • Istio » Istio » Version: 1.3.5
    cpe:2.3:a:istio:istio:1.3.5
  • Istio » Istio » Version: 1.3.6
    cpe:2.3:a:istio:istio:1.3.6
  • Istio » Istio » Version: 1.3.7
    cpe:2.3:a:istio:istio:1.3.7
  • Istio » Istio » Version: 1.4.0
    cpe:2.3:a:istio:istio:1.4.0
  • Istio » Istio » Version: 1.4.1
    cpe:2.3:a:istio:istio:1.4.1
  • Istio » Istio » Version: 1.4.2
    cpe:2.3:a:istio:istio:1.4.2
  • Istio » Istio » Version: 1.4.3
    cpe:2.3:a:istio:istio:1.4.3
  • Redhat » Openshift Service Mesh » Version: 1.0
    cpe:2.3:a:redhat:openshift_service_mesh:1.0
  • Redhat » Enterprise Linux » Version: 8.0
    cpe:2.3:o:redhat:enterprise_linux:8.0


Contact Us

Shodan ® - All rights reserved