NeuVector 的 JWT 验证器能够接受同一 RSA 签名字段的不同 Base64URL 编码形式(非规范编码)。因此,攻击者若持有一个尚未过期但已在 NeuVector 中登出的有效 JWT,只要该令牌的有效期尚未结束,就可以继续使用该令牌,而无需重新登录,因为验证器会接受其 RSA 签名字段的等效不同写法。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78428 | 8.0 HIGH | Flaw in Nuevector can result in one user receiving another user's authenticated session wh |
| CVE-2026-78425 | 7.6 HIGH | SAML Audience Confusion Allows Cross-SP Authentication |
| CVE-2026-78427 | 4.3 MEDIUM | Admission Control Bypass via Hardcoded Sidecar Image Exemption |
No comments yet