High severityNVD Advisory· Published Apr 27, 2020· Updated Aug 4, 2024
CVE-2020-1762
CVE-2020-1762
Description
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kiali/kialiGo | >= 0.4.0, < 1.15.1 | 1.15.1 |
Affected products
2- [Kiali]/kialiv5Range: >= 0.4.0, < 1.15.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-465w-gg5p-85c9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-1762ghsaADVISORY
- bugzilla.redhat.com/show_bug.cgighsaWEB
- bugzilla.redhat.com/show_bug.cgighsax_refsource_CONFIRMWEB
- github.com/kiali/kiali/commit/93f5cd0b6698e8fe8772afb8f35816f6c086aef1ghsaWEB
- github.com/kiali/kiali/commit/c91a0949683976f621cca213c1193831d63b381cghsaWEB
- kiali.io/news/security-bulletins/kiali-security-001ghsaWEB
- kiali.io/news/security-bulletins/kiali-security-001/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.