Use of Hard-coded Cryptographic Key in KubePi - CVE-2023-22463

 

Use of Hard-coded Cryptographic Key in KubePi - CVE-2023-22463

Published: January 4, 2023 / Updated: August 6, 2026


Vulnerability identifier: #VU140979
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22463
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access.

The vulnerability exists due to the use of hardcoded cryptographic keys in JWT signature verification in the authentication mechanism when processing forged JWT tokens. A remote attacker can supply a forged JWT token to bypass authentication and gain unauthorized access.


Affected software

KubePi

How to mitigate CVE-2023-22463

Install security update from vendor's website.

KubePi - update to 1.6.3

External References

Related Security Bulletins