CVE-2020-1762
published 2020-04-27CVE-2020-1762: An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could…
PriorityP347high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
1.13%
62.6th percentile
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | kiali_kiali | >= 0.4.0 < 1.15.1 | 1.15.1 |
| kiali | kiali | >= 0.4.0 < 1.15.1 | 1.15.1 |
| redhat | openshift_service_mesh | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Insufficient Session Expiration in Kiali in github.com/kiali/kiali
osv·2024-08-21
CVE-2020-1762 Insufficient Session Expiration in Kiali in github.com/kiali/kiali
Insufficient Session Expiration in Kiali in github.com/kiali/kiali
Insufficient Session Expiration in Kiali in github.com/kiali/kiali
OSV
Insufficient Session Expiration in Kiali
osv·2021-05-18
CVE-2020-1762 [HIGH] Insufficient Session Expiration in Kiali
Insufficient Session Expiration in Kiali
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
GHSA
Insufficient Session Expiration in Kiali
ghsa·2021-05-18
CVE-2020-1762 [HIGH] CWE-295 Insufficient Session Expiration in Kiali
Insufficient Session Expiration in Kiali
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
Red Hat
kiali: ignoring JWT claim fields
vendor_redhat·2020-03-25·CVSS 7.0
CVE-2020-1762 [HIGH] CWE-565 kiali: ignoring JWT claim fields
kiali: ignoring JWT claim fields
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
An insufficient JWT validation vulnerability was found in Kiali, versions 0.4.0 to 1.15.0. A remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
No detection rules found.
No public exploits indexed.
2020-04-27
Published