Improper Authentication in KubePi - CVE-2024-36111
Published: July 25, 2024 / Updated: August 5, 2026
Vulnerability details
The vulnerability allows a remote user to bypass JWT token validation and gain unauthorized access.
The vulnerability exists due to improper authentication in JWT token validation when handling authentication tokens. A remote user can present a crafted JWT token to bypass JWT token validation and gain unauthorized access.