Executive brief
KubePi allows malicious actor to login with a forged JWT token via Hardcoded Jwtsigkeys in github.com/KubeOperator/kubepi
Affected products
- Go github.com/KubeOperator/kubepi
Junglewise Threat Intelligence
CVE-2023-22463 · Severity: low · CVSS 3 · Published 2024-08-20
Technologies: github.com/KubeOperator/kubepi (Go). Vendors: Go.
KubePi allows malicious actor to login with a forged JWT token via Hardcoded Jwtsigkeys in github.com/KubeOperator/kubepi