Skip to content

Istio Pilot Misconfiguration Detection

istio-pilot-misconfiguration is a high severity check in the devops category, written in go. Its source is templates/devops/istio/istio-pilot-misconfiguration.go in cert-x-gen-templates.

Detects misconfigured Istio Pilot (istiod) control plane endpoints exposed without authentication. Probes port 8080 (HTTP admin), 15010 (xDS plaintext gRPC), and 15014 (monitoring). Exposure allows service mesh topology enumeration, secret extraction, and potential AuthorizationPolicy bypass.

Field Value
Id istio-pilot-misconfiguration
Severity high
Language go
Category devops
Author BugB Technologies
Template version not recorded
Confidence 90
CVSS not recorded
Weakness CWE-306
Tags istio, service-mesh, kubernetes, misconfiguration, xds, envoy, api-exposure, container-security
Target kind not recorded
Oracle not recorded

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info istio-pilot-misconfiguration

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.