PT-2023-23657 · Neuvector · Neuvector
Dejan Zelic
·
Publicado
2023-10-06
·
Atualizado
2024-10-16
·
CVE-2023-32188
CVSS v4.0
9.4
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
NeuVector versions prior to 5.2.2
Description
A user can reverse engineer the JSON Web Token (JWT) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector, potentially leading to Remote Code Execution (RCE).
Recommendations
For versions prior to 5.2.2, upgrade to NeuVector version 5.2.2 or later and use the latest Helm chart (2.6.3+).
As a temporary workaround, users can replace the Manager & Controller certificate manually by following the instructions provided in the documentation.
However, upgrading to 5.2.2 and replacing the Manager/REST API certificate is recommended to provide additional security enhancements to prevent possible attempted exploit and resulting RCE.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Neuvector