Lucene search

K
cvelistRedhatCVELIST:CVE-2020-1762
HistoryApr 27, 2020 - 8:41 p.m.

CVE-2020-1762

2020-04-2720:41:37
CWE-613
CWE-384
redhat
www.cve.org
7

CVSS3

7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

AI Score

8.4

Confidence

High

EPSS

0.003

Percentile

67.9%

An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.

CNA Affected

[
  {
    "product": "kiali",
    "vendor": "[Kiali]",
    "versions": [
      {
        "status": "affected",
        "version": ">= 0.4.0, < 1.15.1"
      }
    ]
  }
]

CVSS3

7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

AI Score

8.4

Confidence

High

EPSS

0.003

Percentile

67.9%