CVE-2020-1762
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/04/2020
Last modified:
07/11/2023
Description
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:kiali:kiali:*:*:*:*:*:*:*:* | 0.4.0 (including) | 1.15.1 (excluding) |
cpe:2.3:a:redhat:openshift_service_mesh:1.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page