CVE-2022-39388
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue.
There are no known workarounds.
HIGH · CVSS 7.6
EPSS 0.00057
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0