Synced 16 Jun 2026 15:24 UTC Account
← All products

CVE-2022-39388

HIGH severity · CVSS 7.6 · Incorrect authorization
7.6CVSS HIGH

Summary

Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue. There are no known workarounds.

Impact & exploitability

Attack vectorAdjacent
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactLow
Availability impactNone
Exploit probability (EPSS)0%

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://github.com/istio/istio/commit/346260e5115e9fbc65ba8a559bc686e6ca046a32 ↗