CVE-2023-32188: Neuvector
Critical severity, CVSS 9.4. EPSS: 0.6% chance of exploitation in the next 30 days.
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
Affected products
- Neuvector Neuvector: before 0.0.0-20231003121714-be746957ee7c (fixed in 0.0.0-20231003121714-be746957ee7c)
- Suse Neuvector: before 0.0.0-20231003121714-be746957ee7c (fixed in 0.0.0-20231003121714-be746957ee7c)
Published 2024-10-16. Last modified 2026-06-17.