CVE-2023-22644

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
20/09/2023
Last modified:
15/10/2024

Description

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:suse:manager_server:*:*:*:*:*:*:*:* 4.2 (including) 4.2.50-150300.3.66.5 (excluding)
cpe:2.3:a:suse:manager_server:*:*:*:*:*:*:*:* 4.3 (including) 4.3.58-150400.3.46.4 (excluding)