{"id":"GHSA-465w-gg5p-85c9","summary":"Insufficient Session Expiration in Kiali","details":"An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.","aliases":["CVE-2020-1762","GO-2022-0626"],"modified":"2024-08-21T15:27:27.417878Z","published":"2021-05-18T21:09:01Z","database_specific":{"github_reviewed_at":"2021-05-18T20:45:55Z","nvd_published_at":null,"cwe_ids":["CWE-295","CWE-384","CWE-613"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-1762"},{"type":"WEB","url":"https://github.com/kiali/kiali/commit/93f5cd0b6698e8fe8772afb8f35816f6c086aef1"},{"type":"WEB","url":"https://github.com/kiali/kiali/commit/c91a0949683976f621cca213c1193831d63b381c"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1810387"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1762"},{"type":"WEB","url":"https://kiali.io/news/security-bulletins/kiali-security-001"}],"affected":[{"package":{"name":"github.com/kiali/kiali","ecosystem":"Go","purl":"pkg:golang/github.com/kiali/kiali"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.4.0"},{"fixed":"1.15.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-465w-gg5p-85c9/GHSA-465w-gg5p-85c9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}