A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
References
Configurations
Configuration 1 (hide)
|
History
15 Oct 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-1270 | |
Summary | (en) A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE. | |
References |
|
|
15 Oct 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-287 | |
References |
|
|
Summary | (en) A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable. |
15 Oct 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-20 09:15
Updated : 2024-10-15 14:15
NVD link : CVE-2023-22644
Mitre link : CVE-2023-22644
CVE.ORG link : CVE-2023-22644
JSON object : View
Products Affected
suse
- manager_server
CWE
CWE-1270
Generation of Incorrect Security Tokens