PT-2021-13870 · Kiali · Kiali

Mark Cooper

·

Published

2021-05-28

·

Updated

2024-08-21

·

CVE-2021-20278

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Kiali versions prior to 1.31.0
Description: An authentication bypass issue was found when the authentication strategy OpenID is used. The problem arises when Kiali assumes some token validation is handled by the underlying cluster with RBAC enabled, but this validation does not occur when OpenID implicit flow is used with RBAC turned off. This allows a malicious user to bypass authentication.
Recommendations: For versions prior to 1.31.0, update to version 1.31.0 or later to resolve the issue. As a temporary workaround, consider disabling the OpenID authentication strategy or enabling RBAC to prevent exploitation. Restrict access to the implicit flow when using the OpenID authentication strategy to minimize the risk of exploitation.

Fix

Authentication Bypass by Spoofing

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-20278
GHSA-GGJR-2F7V-VHQ4
GO-2022-0700

Affected Products

Kiali