You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Mar 30, 2022. It is now read-only.
Hi all,
We are running OWASP dependency checker and got 3 critical CVSS:
istio-common:1.7.7.1 | Istio Before 1.8.6 and 1.9.x Before 1.9.5 Contains a Remotely Exploitable Vulnerability Where an External Client Can Access Unexpected Services in the Cluster, Bypassing Authorization Checks, When a Gateway Is Configured With AUTO_PASSTHROUGH Routing Configuration.(in istio-common-1.7.7.1.jar)
the CVEs you refer to are for Istio itself. This library here is "just" a client to the Istio custom resources. Seems the detection configuration in the OWASP rule set leads to a false positive. This project cannot do anything about it
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Hi all,
We are running OWASP dependency checker and got 3 critical CVSS:
What is your recommendation to solve this?
Thanks!
The text was updated successfully, but these errors were encountered: