SB2023010457 - Use of Hard-coded Cryptographic Key in KubePi



SB2023010457 - Use of Hard-coded Cryptographic Key in KubePi

Published: January 4, 2023 Updated: August 5, 2026

Security Bulletin ID SB2023010457
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use of Hard-coded Cryptographic Key (CVE-ID: N/A)

CWE-ID: CWE-321 - Use of Hard-coded Cryptographic Key

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access.

The vulnerability exists due to the use of hardcoded cryptographic keys in JWT signature verification in the authentication mechanism when processing forged JWT tokens. A remote attacker can supply a forged JWT token to bypass authentication and gain unauthorized access.


Remediation

Install update from vendor's website.