CVE-2021-34824
HIGHIstio 1.8.0-1.9.5 and 1.10.0-1.10.1 - Unauthenticated Credential Access via Gateway and DestinationRule
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-34824. PoCs published by rsalmond.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2021-34824, an Istio vulnerability allowing unauthorized access to Kubernetes secrets. It includes scripts and manifests to deploy vulnerable and patched Istio versions, demonstrating the secret exposure via TLS termination tests.
Description
Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2021-34824, an Istio vulnerability allowing unauthorized access to Kubernetes secrets. It includes scripts and manifests to deploy vulnerable and patched Istio versions, demonstrating the secret exposure via TLS termination tests.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H