Hard coded cryptographic key in Kiali
High severity
GitHub Reviewed
Published
May 18, 2021
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Description
Reviewed
May 6, 2021
Published to the GitHub Advisory Database
May 18, 2021
Last updated
Oct 2, 2023
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
References