Security Considerations on Istio’s CRDs with Namespace-based Multi-Tenancy (opens in new tab)
We reported a possible Man-in-the-Middle (MitM) attack scenario in which a VirtualService can redirect or intercept traffic within the service mesh. This affects Namespace-based Multi-Tenancy clusters where tenants have the permissions to deploy Istio resources (networking.istio.io/v1).
Read the original article