content/en/news/releases/1.3.x/announcing-1.3.7/index.md
This release includes bug fixes to improve robustness. This release note describes what's different between Istio 1.3.6 and Istio 1.3.7.
{{< relnote >}}
PKCS#8 private keys in Citadel agent (Issue 19948).securityContext, allowing PodSecurityPolicies to properly validate injected deployments (Issue 17318).lifecycle for proxy containers.CVE-2020-8843: Under certain circumstances it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts x-istio-attributes header at ingress that can be used to affect policy decisions when Mixer policy selectively applies to source equal to ingress. Istio 1.3 to 1.3.6 is vulnerable.