CVE-2022-39278 is a request processing error in the Istio control plane (istiod) affecting versions prior to 1.15.2, 1.14.5, and 1.13.9. A malicious, unauthenticated attacker can crash the control plane by sending a specially crafted or oversized message to the publicly exposed Kubernetes validating or mutating webhook service on port 15017. This vulnerability has a CVSS score of 7.5 (High) due to its network attack vector, low attack complexity, and high impact on availability, with no confidentiality or integrity impact. While typically only reachable within the cluster, certain deployments, like external istiod topologies, expose this port publicly. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.9CPE matchmatch criteria | cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* | ||
>= 1.14.0, < 1.14.5CPE matchmatch criteria | cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* | ||
>= 1.15.0, < 1.15.2CPE matchmatch criteria | cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.