PT-2023-23657 · Neuvector · Neuvector
Dejan Zelic
·
Published
2023-10-06
·
Updated
2024-10-16
·
CVE-2023-32188
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
NeuVector versions prior to 5.2.2
Description
A user can reverse engineer the JSON Web Token (JWT) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector, potentially leading to Remote Code Execution (RCE).
Recommendations
For versions prior to 5.2.2, upgrade to NeuVector version 5.2.2 or later and use the latest Helm chart (2.6.3+).
As a temporary workaround, users can replace the Manager & Controller certificate manually by following the instructions provided in the documentation.
However, upgrading to 5.2.2 and replacing the Manager/REST API certificate is recommended to provide additional security enhancements to prevent possible attempted exploit and resulting RCE.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neuvector