{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-11T15:27:45.139","vulnerabilities":[{"cve":{"id":"CVE-2022-39278","sourceIdentifier":"security-advisories@github.com","published":"2022-10-13T23:15:11.033","lastModified":"2024-11-21T07:17:56.580","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted or oversized message which results in the control plane crashing when the Kubernetes validating or mutating webhook service is exposed publicly. This endpoint is served over TLS port 15017, but does not require any authentication from the attacker. For simple installations, Istiod is typically only reachable from within the cluster, limiting the blast radius. However, for some deployments, especially external istiod topologies, this port is exposed over the public internet. Versions 1.15.2, 1.14.5, and 1.13.9 contain patches for this issue. There are no effective workarounds, beyond upgrading. This bug is due to an error in `regexp.Compile` in Go."},{"lang":"es","value":"Istio es una malla de servicios abierta e independiente de la plataforma que proporciona administración de tráfico, aplicación de políticas y recopilación de telemetría. En versiones anteriores a 1.15.2, 1.14.5, y 1.13.9, el plano de control de Istio, istiod, es vulnerable a un error de procesamiento de peticiones, permitiendo a un atacante malicioso que envíe un mensaje especialmente diseñado o de gran tamaño que resulte en el bloqueo del plano de control cuando el servicio de webhooks de comprobación o mutación de Kubernetes está expuesto públicamente. Este endpoint es servido a través del puerto 15017 de TLS, pero no requiere ninguna autenticación por parte del atacante. Para instalaciones sencillas, Istiod normalmente sólo es alcanzable desde dentro del clúster, limitando el radio de explosión. Sin embargo, para algunos despliegues, especialmente las topologías de istiod externas, este puerto está expuesto a través de la Internet pública. Las versiones 1.15.2, 1.14.5 y 1.13.9 contienen parches para este problema. no se presentan mitigaciones efectivas, más allá de la actualización. Este bug es debido a un error en el archivo \"regexp.Compile\" en Go"}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*","versionEndExcluding":"1.13.9","matchCriteriaId":"29E9412C-C649-4DE8-98E6-4E1F48048156"},{"vulnerable":true,"criteria":"cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*","versionStartIncluding":"1.14.0","versionEndExcluding":"1.14.5","matchCriteriaId":"A330CF8F-60D8-4C9A-94E2-4F9EA328D801"},{"vulnerable":true,"criteria":"cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*","versionStartIncluding":"1.15.0","versionEndExcluding":"1.15.2","matchCriteriaId":"C0FE7223-1751-420F-AC19-7A6A98BC630C"}]}]}],"references":[{"url":"https://github.com/istio/istio/security/advisories/GHSA-86vr-4wcv-mm9w","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://istio.io/latest/news/releases/1.13.x/announcing-1.13.9/","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://istio.io/latest/news/releases/1.15.x/announcing-1.15.2/","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://istio.io/news/releases/1.14.x/announcing-1.14.5/","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://github.com/istio/istio/security/advisories/GHSA-86vr-4wcv-mm9w","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://istio.io/latest/news/releases/1.13.x/announcing-1.13.9/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://istio.io/latest/news/releases/1.15.x/announcing-1.15.2/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://istio.io/news/releases/1.14.x/announcing-1.14.5/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}