Kiali is a visualization and management console for service meshes deployed in Kubernetes environments, and its vulnerability profile centers on authentication and access-control weaknesses including authentication bypass, improper session management, injection flaws, and output neutralization issues. These vulnerability classes reflect the security boundary demands of a dashboard component exposed to users and integrated with cluster orchestration platforms. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kiali over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1764HIGH A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating | Mar 26, 2020 | 8.6 | 22 | NO | NO |
CVE-2021-20278MEDIUM An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some | May 28, 2021 | 6.5 | 21 | NO | NO |
CVE-2020-1762HIGH An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by s | Apr 27, 2020 | 8.6 | 21 | NO | NO |
CVE-2022-3962MEDIUM A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This i | Sep 23, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kiali.
Media articles that mention a CVE ID that affects a product developed by Kiali — matched by CVE ID, not by vendor name.