Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/istio/istio
  4. ›
  5. GMS-2022-6564

GMS-2022-6564: Duplicate of ./go/github.com/istio/istio/CVE-2022-39388.yml

November 9, 2022

User can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane.

References

  • github.com/advisories/GHSA-6c6p-h79f-g6p4
  • github.com/istio/istio/commit/346260e5115e9fbc65ba8a559bc686e6ca046a32
  • github.com/istio/istio/commit/9a643e270421560afb2630e00f76d46a55499df9
  • github.com/istio/istio/security/advisories/GHSA-6c6p-h79f-g6p4
  • istio.io/latest/news/releases/1.15.x/announcing-1.15.3/

Code Behaviors & Features

Detect and mitigate GMS-2022-6564 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.15.0-beta.0 before 1.15.3

Fixed versions

  • 1.15.3

Solution

Upgrade to version 1.15.3 or above.

Source file

go/github.com/istio/istio/GMS-2022-6564.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:43 +0000.