QID 995533
Date Published: 2023-10-09
QID 995533: GO (Go) Security Update for github.com/neuvector/neuvector (GHSA-622h-h2p8-743x)
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-622h-h2p8-743x for updates and patch information.
Vendor References
- GHSA-622h-h2p8-743x -
github.com/advisories/GHSA-622h-h2p8-743x
CVEs related to QID 995533
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-622h-h2p8-743x | github.com/neuvector/neuvector |
|