CVE-2019-25014
29.01.2021, 06:15
A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting in a denial of service to the istio-pilot application).Enginsight
Vendor | Product | Version |
---|---|---|
istio | istio | 𝑥 ≤ 1.4.9 |
redhat | openshift_service_mesh | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration