PT-2020-15041 · Istio · Istio
Published
2020-04-27
·
Updated
2024-08-21
·
CVE-2020-1762
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Kiali versions 0.4.0 through 1.15.0
Description
The issue is related to insufficient JWT validation, allowing a remote attacker to steal a valid JWT cookie and use it to spoof a user session. This could potentially grant privileges to view and alter the Istio configuration.
Recommendations
For Kiali versions 0.4.0 through 1.15.0, update to version 1.15.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the Istio configuration to minimize the risk of exploitation.
Fix
Session Fixation
Improper Certificate Validation
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Istio