Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-465w-gg5p-85c9

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Insufficient Session Expiration in Kiali

An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.

Пакеты

Наименование

github.com/kiali/kiali

go
Затронутые версииВерсия исправления

>= 0.4.0, < 1.15.1

1.15.1

EPSS

Процентиль: 68%
0.00582
Низкий

8.6 High

CVSS3

Дефекты

CWE-295
CWE-384
CWE-613

Связанные уязвимости

CVSS3: 7
redhat
почти 6 лет назад

An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.

CVSS3: 7
nvd
почти 6 лет назад

An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.

EPSS

Процентиль: 68%
0.00582
Низкий

8.6 High

CVSS3

Дефекты

CWE-295
CWE-384
CWE-613