Use of Hard-coded Cryptographic Key in KubePi - CVE-2023-22463
Published: January 4, 2023 / Updated: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access.
The vulnerability exists due to the use of hardcoded cryptographic keys in JWT signature verification in the authentication mechanism when processing forged JWT tokens. A remote attacker can supply a forged JWT token to bypass authentication and gain unauthorized access.