PT-2020-2707 · Istio · Kiali

Published

2020-03-25

·

Updated

2024-08-21

·

CVE-2020-1764

CVSS v2.0

9.7

High

VectorAV:N/AC:L/Au:N/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kiali versions prior to 1.15.1
Description The issue is related to a hard-coded cryptographic key in the default configuration file of Kiali, which is part of the Istio service mesh. This flaw can be exploited by a remote attacker to create self-signed JWT tokens, bypassing Kiali's authentication mechanisms and potentially gaining privileges to view and alter the Istio configuration.
Recommendations For versions prior to 1.15.1, update to version 1.15.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Kiali console to minimize the risk of exploitation. Avoid using the default configuration file until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2020-02783
CVE-2020-1764
GHSA-64RH-R86Q-75FF
GO-2022-0631

Affected Products

Kiali