Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64rh-r86q-75ff

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Hard coded cryptographic key in Kiali

A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.

Пакеты

Наименование

github.com/kiali/kiali

go
Затронутые версииВерсия исправления

< 1.15.1

1.15.1

EPSS

Процентиль: 89%
0.05246
Низкий

8.6 High

CVSS3

Дефекты

CWE-321
CWE-798

Связанные уязвимости

CVSS3: 8.6
redhat
около 5 лет назад

A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.

CVSS3: 8.6
nvd
около 5 лет назад

A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.

CVSS3: 9.4
fstec
около 5 лет назад

Уязвимость консоли управления для сервисной сетки на основе Istio Kiali, связанная с использованием жестко закодированного ключа шифрования, позволяющая нарушителю повысить свои привилегии

oracle-oval
почти 5 лет назад

ELSA-2020-5765: Unbreakable Enterprise kernel-container kata-image kata-runtime kata kubernetes kubernetes istio olcne security update (IMPORTANT)

EPSS

Процентиль: 89%
0.05246
Низкий

8.6 High

CVSS3

Дефекты

CWE-321
CWE-798