Back to Istio Io

ISTIO-SECURITY-2020-007

content/en/news/security/istio-security-2020-007/index.md

latest2.3 KB
Original Source

CVE-2020-8663 is addressed in Envoy by adding a configurable limit on downstream connections. The limit must be configured to mitigate this vulnerability. Perform the following steps to configure limits at the ingress gateway.

{{< security_bulletin >}}

Envoy, and subsequently Istio, are vulnerable to four newly discovered vulnerabilities:

Mitigation

  • For Istio 1.5.x deployments: update to Istio 1.5.7 or later.
  • For Istio 1.6.x deployments: update to Istio 1.6.4 or later.

{{< warning >}} You must take the following additional steps to mitigate CVE-2020-8663. {{< /warning >}}

{{< boilerplate cve-2020-007-configmap >}}

{{< boilerplate "security-vulnerability" >}}