istio.io/content/en/news/security/istio-security-2020-007/index.md

2.7 KiB

title subtitle description cves cvss vector releases publishdate keywords skip_seealso
ISTIO-SECURITY-2020-007 Security Bulletin Multiple denial of service vulnerabilities in Envoy.
CVE-2020-12603
CVE-2020-12605
CVE-2020-8663
CVE-2020-12604
7.5 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1.5 to 1.5.6
1.6 to 1.6.3
2020-06-30
CVE
true

CVE-2020-8663 is addressed in Envoy by adding a configurable limit on downstream connections. The limit must be configured to mitigate this vulnerability. Perform the following steps to configure limits at the ingress gateway.

{{< security_bulletin >}}

Envoy, and subsequently Istio, are vulnerable to four newly discovered vulnerabilities:

Mitigation

  • For Istio 1.5.x deployments: update to Istio 1.5.7 or later.
  • For Istio 1.6.x deployments: update to Istio 1.6.4 or later.

{{< warning >}} You must take the following additional steps to mitigate CVE-2020-8663. {{< /warning >}}

{{< boilerplate cve-2020-007-configmap >}}

{{< boilerplate "security-vulnerability" >}}