PT-2020-2707 · Istio · Kiali
Published
2020-03-25
·
Updated
2024-08-21
·
CVE-2020-1764
CVSS v2.0
9.7
High
| Vector | AV:N/AC:L/Au:N/C:P/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Kiali versions prior to 1.15.1
Description
The issue is related to a hard-coded cryptographic key in the default configuration file of Kiali, which is part of the Istio service mesh. This flaw can be exploited by a remote attacker to create self-signed JWT tokens, bypassing Kiali's authentication mechanisms and potentially gaining privileges to view and alter the Istio configuration.
Recommendations
For versions prior to 1.15.1, update to version 1.15.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Kiali console to minimize the risk of exploitation.
Avoid using the default configuration file until the issue is resolved.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kiali