VYPR

Kong

by Kong

CVEs (4)

  • CVE-2023-39846CriAug 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.

  • CVE-2020-35189CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2023-26987MedMay 1, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

  • CVE-2023-2418LowApr 29, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be…