CVE-2020-1764
published 2020-03-26CVE-2020-1764: A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse…
PriorityP355high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
3.47%
87.7th percentile
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | kiali_kiali | >= 0 < 1.15.1 | 1.15.1 |
| kiali | kiali | < 1.15.1 | 1.15.1 |
| red_hat | kiali | — | — |
| redhat | openshift_service_mesh | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Hard coded cryptographic key in Kiali in github.com/kiali/kiali
osv·2024-08-21
CVE-2020-1764 Hard coded cryptographic key in Kiali in github.com/kiali/kiali
Hard coded cryptographic key in Kiali in github.com/kiali/kiali
Hard coded cryptographic key in Kiali in github.com/kiali/kiali
OSV
Hard coded cryptographic key in Kiali
osv·2021-05-18
CVE-2020-1764 [HIGH] Hard coded cryptographic key in Kiali
Hard coded cryptographic key in Kiali
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
GHSA
Hard coded cryptographic key in Kiali
ghsa·2021-05-18
CVE-2020-1764 [HIGH] CWE-321 Hard coded cryptographic key in Kiali
Hard coded cryptographic key in Kiali
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
Red Hat
kiali: JWT cookie uses default signing key
vendor_redhat·2020-03-25·CVSS 8.6
CVE-2020-1764 [HIGH] CWE-321 kiali: JWT cookie uses default signing key
kiali: JWT cookie uses default signing key
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
Statement: If exploited, an attacker can perform all Kiali admin functions via the API including:
- View the logs of a pod
- View Istio
No detection rules found.
No public exploits indexed.
2020-03-26
Published