Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22830
HistoryMar 31, 2020 - 3:59 a.m.

Authentication Bypass

2020-03-3103:59:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.002

Percentile

59.1%

github.com/kiali/kiali is vulnerable to authentication bypass. The default signing key for JWT cookies is known in the source, allowing an attacker to forge credentials and use it to gain access to the application.