Back to Istio Io

Announcing Istio 1.6.8

content/en/news/releases/1.6.x/announcing-1.6.8/index.md

latest773 B
Original Source

This release fixes the security vulnerability described in our August 11th, 2020 news post.

This release contains bug fixes to improve robustness. These release notes describe what’s different between Istio 1.6.7 and Istio 1.6.8.

{{< relnote >}}

Security update

  • CVE-2020-16844: Callers to TCP services that have a defined Authorization Policies with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields will never be denied access.