REDHAT-BUG-2446344: High severity Istio Istio vulnerability
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
istioto a version that resolves this vulnerability.Fixed in 1.29.1 - Upgrade
Upgrade
istioto a version that resolves this vulnerability.Fixed in 1.28.5 - Upgrade
Upgrade
istioto a version that resolves this vulnerability.Fixed in 1.27.8
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2446344?
The severity of REDHAT-BUG-2446344 is categorized as high with a score of 7.
How do I fix REDHAT-BUG-2446344?
To fix REDHAT-BUG-2446344, upgrade Istio to versions 1.29.1, 1.28.5, or 1.27.8 or later.
What is the main issue described in REDHAT-BUG-2446344?
The main issue in REDHAT-BUG-2446344 is that an unavailable JWKS resolver can expose hardcoded defaults, compromising security.
Who is impacted by REDHAT-BUG-2446344?
Users of Istio prior to versions 1.29.1, 1.28.5, and 1.27.8 are impacted by REDHAT-BUG-2446344.
What does the vulnerability REDHAT-BUG-2446344 affect in Istio?
REDHAT-BUG-2446344 affects the security of microservices by improperly handling JWKS resolver failures.