CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.6. It may be remotely exploitable.
CVE
CVE-2020-1764
Severity
HIGH
CVSS
8.6
EPSS
3.47%
Original NVD Description
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.
Related CVEs
Other vulnerabilities affecting the same vendor(s)