{"id":"GHSA-64rh-r86q-75ff","summary":"Hard coded cryptographic key in Kiali","details":"A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.","aliases":["CVE-2020-1764","GO-2022-0631"],"modified":"2024-08-21T15:26:45.640199Z","published":"2021-05-18T18:28:59Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-05-06T21:51:32Z","nvd_published_at":null,"cwe_ids":["CWE-321","CWE-798"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-1764"},{"type":"WEB","url":"https://github.com/kiali/kiali/commit/93f5cd0b6698e8fe8772afb8f35816f6c086aef1"},{"type":"WEB","url":"https://github.com/kiali/kiali/commit/ac7bd6c7ddb2e01356e21d360dd1c718a90706ad"},{"type":"WEB","url":"https://github.com/kiali/kiali/commit/ce48af57113c805a25179aaab1a0fac2fb93653f"},{"type":"WEB","url":"https://github.com/kiali/kiali/commit/faed1f5f90efae3df9fd6fb793f00ccc242b3a96"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1810383"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1764"},{"type":"WEB","url":"https://github.com/jpts/cve-2020-1764-poc"},{"type":"WEB","url":"https://kiali.io/news/security-bulletins/kiali-security-001"}],"affected":[{"package":{"name":"github.com/kiali/kiali","ecosystem":"Go","purl":"pkg:golang/github.com/kiali/kiali"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.15.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-64rh-r86q-75ff/GHSA-64rh-r86q-75ff.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}