CVE-2020-1764
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Exploitability: 3.9 / Impact: 4.7
Source: NVD
Description
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
Affected (2)
Products: Kiali: Kiali · Redhat: Openshift Service Mesh
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
Related CWEs
References (4)
Source: secalert@redhat.com
Issue TrackingMitigationThird Party Advisory
Source: secalert@redhat.com
ExploitMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationVendor Advisory
Timeline
No history available yet.