A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
The JWT token used in NeuVector for authentication to the Manager panel and API can be reverse-engineered by a logged-in user. Based on token analysis, an attacker is able to construct a forged but cryptographically valid JWT token. Such a prepared token enables operation in the context of any other user or role, including with administrative privileges, which opens the door to performing malicious operations leading to RCE.
An attacker can take full control of a NeuVector instance by executing arbitrary code on the server (RCE) and obtaining high privileges in both the system and related infrastructure.
Patches available from the vendor should be applied in accordance with the references (https://github.com/neuvector/neuvector/security/advisories/GHSA-622h-h2p8-743x and https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32188).
NeuVector product (Manager and API) — specific versions indicated in vendor references (GHSA-622h-h2p8-743x and bugzilla.suse.com).
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X