VYPR

Kiali

by Kiali

Source repositories

CVEs (4)

  • CVE-2020-1764HigMar 26, 2020
    risk 0.49cvss 8.6epss 0.03

    A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining…

  • CVE-2020-1762HigApr 27, 2020
    risk 0.39cvss 7.0epss 0.01

    An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to…

  • CVE-2021-20278MedMay 28, 2021
    risk 0.35cvss 6.5epss 0.01

    An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some of the token validation is handled by the underlying cluster. When OpenID `implicit flow` is used…

  • CVE-2022-3962MedSep 23, 2023
    risk 0.21cvss 4.3epss 0.01

    A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved…