CVE-2022-39388

HIGH

Istio 1.15.0-1.15.2 and 1.15.0-beta.0-1.15.3 - Incorrect Authorization via Workload Identity Impersonation

Title source: llm
STIX 2.1

Description

Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue. There are no known workarounds.

Scores

CVSS v3 7.6
EPSS 0.0046
EPSS Percentile 36.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
istio/istio 1.15.0 - 1.15.2
istio/istio 1.15.0-beta.0 - 1.15.3Go
Published Nov 10, 2022
Tracked Since Feb 18, 2026