QID 982543
QID 982543: Go (go) Security Update for github.com/kiali/kiali (GHSA-465w-gg5p-85c9)
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-465w-gg5p-85c9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-465w-gg5p-85c9 -
github.com/advisories/GHSA-465w-gg5p-85c9
CVEs related to QID 982543
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-465w-gg5p-85c9 | github.com/kiali/kiali |
|