#VU27379 Insufficient Session Expiration in Kiali - CVE-2020-1762
Published: April 28, 2020
Kiali
Kiali
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an insufficient JWT validation. A remote non-authenticated attacker can steal a valid JWT cookie and gain unauthorized access to session that belongs to another user, possibly gain privileges to view and alter the Istio configuration.