Istio audit report - ADA Logics - 2023-01-30 - v1.0summarised 6 fuzzers written and added to Istio's OSS-Fuzz integration 1 CVE found in Golang 1 vulnerability found that affected Googles managed Istio offering 11 issues found ● 5 system resource exhaustion affected Googleʼs managed Istio offering, and it led to further investigation that revealed a vulnerability in Golang itself. The finding was reported by the auditing team to the Istio maintainers, because connection, which could lead to a denial of service scenario if a large request was sent. This is a vulnerability, however, to be vulnerable, users would need the MultiplexHTTP option configured - used by some0 码力 | 55 页 | 703.94 KB | 1 年前3
IstioCon2023 Welcome Keynotehow to report bugs, in code or in documentation. ● The Istio security team responds rapidly to vulnerability reports. Read how to submit an issue. Become a Contributor ● The Istio Community README is the0 码力 | 14 页 | 1.31 MB | 1 年前3
Istio Security Assessmentabused in the event of a workload compromise or the exploitation of a server-side request forgery vulnerability. In the case of the latter, this could enable a denial of service vector by sending a request0 码力 | 51 页 | 849.66 KB | 1 年前3
共 3 条
- 1













