Use of Hard-coded Cryptographic Key in Kiali - CVE-2020-1764

 

Use of Hard-coded Cryptographic Key in Kiali - CVE-2020-1764

Published: April 28, 2020 / Updated: July 15, 2020


Vulnerability identifier: #VU27380
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1764
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to the system.

The vulnerability exists due to presence of a hard-coded cryptographic key in the default configuration file. A remote attacker can create their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.


Affected software

Kiali

How to mitigate CVE-2020-1764

Install updates from vendor's website.

Kiali - update to 1.15.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins