KubePi's JWT token validation has a defect
KubePi, a Kubernetes management panel, has a flaw in its JWT token validation where the default security key is empty. An attacker can create fake login tokens using this empty key to bypass authentication and gain unauthorized access to the system.
CVE-2024-36111 affects KubePi versions 1.6.3 through 1.7.x, where JWT verification uses an empty key despite configuration logic attempting to generate a random replacement; this allows an unauthenticated attacker to forge valid JWT tokens and bypass authentication controls to access the Kubernetes management backend. The vulnerability exists in the token verification logic which does not properly utilize the generated key during actual validation.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →