A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Neuvector
Neuvector neuvector |
|
CPEs | cpe:2.3:a:neuvector:neuvector:*:*:*:*:*:*:*:* | |
Vendors & Products |
Neuvector
Neuvector neuvector |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE. | |
Title | JWT token compromise can allow malicious actions including Remote Code Execution (RCE) | |
Weaknesses | CWE-1270 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: suse
Published: 2024-10-16T08:25:59.699Z
Updated: 2024-10-16T17:25:54.710Z
Reserved: 2023-05-04T08:30:59.321Z
Link: CVE-2023-32188
Vulnrichment
Updated: 2024-10-16T16:27:55.465Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T09:15:03.260
Modified: 2024-10-16T16:38:14.557
Link: CVE-2023-32188
Redhat
No data.