CVE-2020-14306 is an incorrect access control flaw affecting all versions through 1.1.3 of the openshift-service-mesh/istio-rhel8-operator. This vulnerability allows an attacker with basic cluster access to deploy custom gateways or pods to any namespace, potentially compromising privileged service account tokens. Rated 8.8 HIGH on CVSS, it poses a significant threat to data confidentiality, integrity, and system availability, with a low attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.3CPE matchmatch criteria | cpe:2.3:a:istio-operator_project:istio-operator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.