KubePi allows malicious actor to login with a forged JWT token via Hardcoded Jwtsigkeys
Discription
### Summary
The jwt authentication function of kubepi Read More
References
https://github.com/KubeOperator/KubePi/security/advisories/GHSA-vjhf-8vqx-vqpqhttps://nvd.nist.gov/vuln/detail/CVE-2023-22463https://github.com/KubeOperator/KubePi/commit/3be58b8df5bc05d2343c30371dd5fcf6a9fbbf8bhttps://github.com/KubeOperator/KubePi/blob/da784f5532ea2495b92708cacb32703bff3a45a3/internal/api/v1/session/session.go#L35https://github.com/KubeOperator/KubePi/releases/tag/v1.6.3https://github.com/advisories/GHSA-vjhf-8vqx-vqpqBack to Main