← voltar
CVE-2020-1764highCWE-321

CVE-2020-1764

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 8.6epss 3.5%
probabilidade de exploração
3.5%top 12% das CVEs
exploração observada
nãonenhuma fonte reporta
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Produtos afetados
Red Hat · kiali