Skip to content

x/vulndb: potential Go vuln in istio.io/istio: GHSA-hqxw-mm44-gc4r #1486

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
GoVulnBot opened this issue Jan 11, 2023 · 1 comment
Closed

Comments

@GoVulnBot
Copy link

In GitHub Security Advisory GHSA-hqxw-mm44-gc4r, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
istio.io/istio 1.11.1 = 1.11.0

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: istio.io/istio
    versions:
      - introduced: TODO (earliest fixed "1.11.1", vuln range "= 1.11.0")
    packages:
      - package: istio.io/istio
  - module: istio.io/istio
    versions:
      - introduced: 1.10.0
        fixed: 1.10.4
    packages:
      - package: istio.io/istio
  - module: istio.io/istio
    versions:
      - fixed: 1.9.8
    packages:
      - package: istio.io/istio
description: "### Impact\nIstio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain
    a remotely exploitable vulnerability where an HTTP request with `#fragment` in
    the path may bypass Istio’s URI path based authorization policies. \n\n### Patches\n*
    Istio 1.11.1 and above\n* Istio 1.10.4 and above\n* Istio 1.9.8 and above\n\n###
    Workarounds\nA Lua filter may be written to normalize the path.  This is similar
    to the Path normalization presented in the [Security Best Practices](https://istio.io/latest/docs/ops/best-practices/security/#case-normalization)
    guide.\n\n### References\nMore details can be found in the [Istio Security Bulletin](https://istio.io/latest/news/security/istio-security-2021-008)\n\n###
    For more information\nIf you have any questions or comments about this advisory,
    please email us at [email protected]\n"
cves:
  - CVE-2021-39156
ghsas:
  - GHSA-hqxw-mm44-gc4r

@tatianab
Copy link
Contributor

Duplicate of #932

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants