Hi, If the Istio 1.7 is not listed then most likely it was not vetted, but that does not necessarily mean that it would not work. Sandbox and good backup should tell you the absolute answer.
... View more
Hi, I think it would be appropriate to patch vulnerabilities like this without waiting for a hotfix, however, remember to always have a dev/sandbox to test in with a good backup. Lastly, always upgrade to the fixed version exactly to avoid false positives.
... View more