SB2023010457 - Use of Hard-coded Cryptographic Key in KubePi
Published: January 4, 2023 Updated: August 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Hard-coded Cryptographic Key (CVE-ID: N/A)
CWE-ID: CWE-321 - Use of Hard-coded Cryptographic Key
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access.
The vulnerability exists due to the use of hardcoded cryptographic keys in JWT signature verification in the authentication mechanism when processing forged JWT tokens. A remote attacker can supply a forged JWT token to bypass authentication and gain unauthorized access.
Remediation
Install update from vendor's website.