← volver
CVE-2020-1764

CVE-2020-1764

CVSS 8.6 HIGHEPSS 3.5%CWE-321
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Productos afectados
Red Hat · kiali

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →