JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
CVE-2023-22644
9.4CRITICAL
What is CVE-2023-22644?
The vulnerability allows an attacker to reverse engineer the JSON Web Token (JWT) utilized in the authentication process for Manager and API access in NeuVector. By successfully forging a valid NeuVector token, an unauthorized user could engage in harmful activities, potentially leading to remote code execution. This exploitation poses significant risks to the integrity and security of deployment environments that rely on NeuVector.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
neuvector 0 < 0.0.0-20231003121714-be746957ee7c
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dejan Zelic at Offensive Security