SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  KubePi k8s JWT Authentication Bypass

Category: WEB-ATTACKS      

The jwt authentication function of kubepi less or equal v1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker can forge any jwt token to take over the administrator account of any online project.


Relevant Information