CVE-2021-34824

HIGH

Istio <1.11 - RCE

Title source: llm
STIX 2.1

Description

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

Exploits (1)

nomisec WORKING POC
by rsalmond · poc
https://github.com/rsalmond/CVE-2021-34824

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/istio/istio/releases

Scores

CVSS v3 8.8
EPSS 0.0184
EPSS Percentile 83.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
istio/istio 1.8.0 - 1.9.6
Published Jun 29, 2021
Tracked Since Feb 18, 2026