CRITICAL🇵🇱 Wersja polska

CVE-2023-32188

CVSS 9.4v4.0pub. 2024-10-16upd. 2026-04-15

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

🤖 AI Analysis
How it works

The JWT token used in NeuVector for authentication to the Manager panel and API can be reverse-engineered by a logged-in user. Based on token analysis, an attacker is able to construct a forged but cryptographically valid JWT token. Such a prepared token enables operation in the context of any other user or role, including with administrative privileges, which opens the door to performing malicious operations leading to RCE.

Impact

An attacker can take full control of a NeuVector instance by executing arbitrary code on the server (RCE) and obtaining high privileges in both the system and related infrastructure.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references (https://github.com/neuvector/neuvector/security/advisories/GHSA-622h-h2p8-743x and https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32188).

Who is affected

NeuVector product (Manager and API) — specific versions indicated in vendor references (GHSA-622h-h2p8-743x and bugzilla.suse.com).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References