Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22803
HistoryMar 27, 2020 - 2:27 a.m.

Spoofable User Session

2020-03-2702:27:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.003

Percentile

67.9%

kiali uses spoofable user session. The attack is possible due to Insufficient JWT Session Expiration validation, leading to Session Fixation and privilege escalation.

EPSS

0.003

Percentile

67.9%