CVE-2024-8901: Lack of JWT issuer and signer validation

Published Oct 21, 2024
·
Updated

The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio/tree/master provides an OIDC authentication mechanism that was integrated into the open source Kubeflow project. The adapter uses JWT for authentication, but lacks proper signer and issuer validation. In deployments of ALB that ignore security best practices, where ALB targets are directly exposed to internet traffic, an actor can provide a JWT signed by an untrusted entity in order to spoof OIDC-federated sessions and successfully bypass authentication.

The repository/package has been deprecated, is end of life, and is no longer supported. As a security best practice, ensure that your ELB targets (e.g. EC2 Instances, Fargate Tasks etc.) do not have public IP addresses. Ensure any forked or derivative code validate that the signer attribute in the JWT match the ARN of the Application Load Balancer that the service is configured to use.

Affected Software

2 affected components
AWS ALB Route Directive Adapter For Istio
kubeflow kubeflow

Event History

Oct 21, 2024
CVE Published
via MITRE·11:19 PM
Data Sourced
via MITRE·11:19 PM
DescriptionSeverityWeakness
Oct 22, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-8901?

The severity of CVE-2024-8901 is classified as high due to the potential impact on OIDC authentication mechanisms.

2

How do I fix CVE-2024-8901?

To fix CVE-2024-8901, implement updated authentication and authorization measures for the AWS ALB Route Directive Adapter for Istio.

3

What systems are affected by CVE-2024-8901?

CVE-2024-8901 affects the AWS ALB Route Directive Adapter for Istio and the Kubeflow project.

4

What types of vulnerabilities does CVE-2024-8901 address?

CVE-2024-8901 addresses vulnerabilities related to insufficient JWT authentication in OIDC implementations.

5

Is there a patch for CVE-2024-8901?

Yes, there is a patch available that can be applied to mitigate the vulnerabilities associated with CVE-2024-8901.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203