CVE-2020-1764

A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
Configurations

Configuration 1

cpe:2.3:a:kiali:kiali:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_service_mesh:1.0:*:*:*:*:*:*:*

Information

Published : 2020-03-26 01:15

Updated : 2020-05-28 05:21


NVD link : CVE-2020-1764

Mitre link : CVE-2020-1764

Products Affected
No products.
CWE