An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
{
"unresolved_ranges": [
{
"vendor_product": "redhat:openshift_service_mesh",
"cpes": [
"cpe:2.3:a:redhat:openshift_service_mesh:1.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "1.0"
}
]
}
]
}