CVE-2021-34824

HIGH

Istio 1.8.0-1.9.5 and 1.10.0-1.10.1 - Unauthenticated Credential Access via Gateway and DestinationRule

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-34824. PoCs published by rsalmond.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2021-34824, an Istio vulnerability allowing unauthorized access to Kubernetes secrets. It includes scripts and manifests to deploy vulnerable and patched Istio versions, demonstrating the secret exposure via TLS termination tests.

Description

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

Exploits (1)

nomisec WORKING POC
by rsalmond · poc
https://github.com/rsalmond/CVE-2021-34824

This repository contains a functional proof-of-concept for CVE-2021-34824, an Istio vulnerability allowing unauthorized access to Kubernetes secrets. It includes scripts and manifests to deploy vulnerable and patched Istio versions, demonstrating the secret exposure via TLS termination tests.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Istio 1.10.1 (fixed in 1.10.2)
No auth needed
Prerequisites: Kubernetes cluster with admin access · Istio installed
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/istio/istio/releases

Scores

CVSS v3 8.8
EPSS 0.0197
EPSS Percentile 78.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
istio/istio 1.8.0 - 1.9.6
Published Jun 29, 2021
Tracked Since Feb 18, 2026