MidnightBSD

Advisories for konghq

CVE-2020-11710 HIGH

An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself. In reality, this issue is not associated with any version of the Kong gateway. As such, the description stating ‘An issue was discovered in docker-kong (for Kong) through 2.0.3.’ is incorrect. This issue only occurs if a user decided to spin up Kong via docker-compose without following the security documentation. The docker-compose template is meant for users to quickly get started with Kong, and is meant for development purposes only. 2) Incorrect Patch Links - The CVE currently points to a documentation improvement as a “Patch” link: https://github.com/Kong/docs.konghq.com/commit/d693827c32144943a2f45abc017c1321b33ff611.This link actually points to an improvement Kong Inc made for fool-proofing. However, instructions for how to protect the admin API were already well-documented here: https://docs.konghq.com/2.0.x/secure-admin-api/#network-layer-access-restrictions , which was first published back in 2017 (as shown in this commit: https://github.com/Kong/docs.konghq.com/commit/e99cf875d875dd84fdb751079ac37882c9972949) Lastly, the hyperlink to https://github.com/Kong/kong (an unrelated Github Repo to this issue) on the Hyperlink list does not include any meaningful information on this topic.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
konghq docker-kong *
CVE-2020-36661 LOW

A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The manipulation leads to inefficient regular expression complexity. Upgrading to version 0.5.9-1 is able to address this issue. The patch is identified as d632e5df43a2928fd537784a99a79dec288bf01b. It is recommended to upgrade the affected component. VDB-220642 is the identifier assigned to this vulnerability.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-1333,

Products Affected

Vendor Product Version
konghq multipart 0.5.8-1
CVE-2021-27306 MEDIUM

An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-706,

Products Affected

Vendor Product Version
konghq kong_gateway *
CVE-2023-2418 LOW

A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The associated identifier of this vulnerability is VDB-227715.

CVSS 2.0

Severity: LOW

Problem Type: CWE-330,

Products Affected

Vendor Product Version
konghq kong 2.8.3
CVE-2023-40299

Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 1.8 5.9

Products Affected

Vendor Product Version
konghq insomnia 2023.4.0
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
amazon opensearch_data_prepper *
microsoft windows_server_2022 -
microsoft windows_10_21h2 *
cisco prime_access_registrar *
cisco ultra_cloud_core_-_session_management_function *
facebook proxygen *
netapp astra_control_center -
redhat openshift_dev_spaces -
redhat run_once_duration_override_operator -
apache apisix *
f5 nginx_plus *
cisco unified_contact_center_domain_manager -
redhat advanced_cluster_security 4.0
debian debian_linux 11.0
varnish_cache_project varnish_cache *
f5 big-ip_domain_name_system *
redhat jboss_a-mq 7
redhat jboss_a-mq_streams -
redhat single_sign-on 7.0
cisco ultra_cloud_core_-_policy_control_function 2024.01.0
f5 nginx *
microsoft windows_server_2016 -
redhat openshift_pipelines -
microsoft .net *
redhat jboss_fuse 6.0.0
caddyserver caddy *
f5 big-ip_websafe *
redhat openshift_distributed_tracing -
redhat openshift_virtualization 4
cisco telepresence_video_communication_server *
cisco nx-os *
f5 big-ip_ddos_hybrid_defender *
redhat build_of_quarkus -
nodejs node.js *
cisco fog_director *
redhat integration_camel_for_spring_boot -
redhat web_terminal -
f5 big-ip_analytics *
f5 big-ip_link_controller 17.1.0
redhat cert-manager_operator_for_red_hat_openshift -
redhat enterprise_linux 6.0
netapp oncommand_insight -
redhat openshift_serverless -
microsoft azure_kubernetes_service *
redhat integration_camel_k -
linkerd linkerd 2.13.1
jenkins jenkins *
grpc grpc 1.57.0
microsoft visual_studio_2022 *
f5 big-ip_link_controller *
redhat advanced_cluster_security 3.0
f5 big-ip_application_acceleration_manager 17.1.0
envoyproxy envoy 1.25.9
redhat logging_subsystem_for_red_hat_openshift -
redhat jboss_enterprise_application_platform 6.0.0
redhat certification_for_red_hat_enterprise_linux 9.0
akka http_server *
redhat openshift_data_science -
f5 big-ip_application_visibility_and_reporting 17.1.0
redhat network_observability_operator -
cisco unified_attendant_console_advanced -
microsoft windows_11_21h2 *
redhat advanced_cluster_management_for_kubernetes 2.0
redhat decision_manager 7.0
redhat jboss_data_grid 7.0.0
dena h2o *
f5 big-ip_application_acceleration_manager *
f5 nginx_plus r29
f5 nginx_plus r30
microsoft cbl-mariner *
microsoft windows_10_1809 *
cisco secure_web_appliance_firmware *
redhat service_telemetry_framework 1.5
traefik traefik *
redhat fence_agents_remediation_operator -
envoyproxy envoy 1.27.0
linkerd linkerd 2.14.0
redhat openshift_api_for_data_protection -
cisco crosswork_zero_touch_provisioning *
f5 big-ip_access_policy_manager *
redhat openshift -
redhat process_automation 7.0
linkerd linkerd 2.13.0
redhat service_interconnect 1.0
cisco crosswork_data_gateway 5.0
f5 big-ip_advanced_web_application_firewall 17.1.0
cisco business_process_automation *
linkerd linkerd *
cisco secure_dynamic_attributes_connector *
redhat openshift_developer_tools_and_services -
redhat openstack_platform 16.1
redhat self_node_remediation_operator -
redhat openshift_container_platform_assisted_installer -
redhat migration_toolkit_for_applications 6.0
f5 big-ip_domain_name_system 17.1.0
cisco crosswork_situation_manager -
konghq kong_gateway *
debian debian_linux 10.0
f5 big-ip_local_traffic_manager *
redhat quay 3.0.0
cisco prime_network_registrar *
golang networking *
f5 big-ip_local_traffic_manager 17.1.0
f5 big-ip_ddos_hybrid_defender 17.1.0
redhat machine_deletion_remediation_operator -
openresty openresty *
redhat migration_toolkit_for_virtualization -
redhat openstack_platform 16.2
redhat node_maintenance_operator -
redhat build_of_optaplanner 8.0
f5 big-ip_advanced_firewall_manager *
cisco ios_xr *
redhat jboss_fuse 7.0.0
fedoraproject fedora 37
redhat integration_service_registry -
f5 big-ip_fraud_protection_service *
redhat enterprise_linux 9.0
redhat openshift_container_platform 4.0
cisco unified_contact_center_management_portal -
cisco crosswork_data_gateway *
cisco firepower_threat_defense *
f5 big-ip_global_traffic_manager 17.1.0
cisco ios_xe *
cisco prime_infrastructure *
cisco ultra_cloud_core_-_policy_control_function *
cisco data_center_network_manager -
eclipse jetty *
linkerd linkerd 2.14.1
redhat enterprise_linux 8.0
redhat openshift_service_mesh 2.0
redhat ansible_automation_platform 2.0
ietf http 2.0
f5 big-ip_webaccelerator 17.1.0
microsoft windows_10_1607 *
redhat openshift_sandboxed_containers -
microsoft windows_server_2019 -
cisco secure_malware_analytics *
redhat certification_for_red_hat_enterprise_linux 8.0
cisco unified_contact_center_enterprise_-_live_data_server *
projectcontour contour *
envoyproxy envoy 1.26.4
microsoft asp.net_core *
fedoraproject fedora 38
cisco connected_mobile_experiences *
apple swiftnio_http/2 *
f5 nginx_ingress_controller *
redhat support_for_spring_boot -
cisco ultra_cloud_core_-_serving_gateway_function *
linecorp armeria *
apache traffic_server *
apache tomcat 11.0.0
redhat openstack_platform 17.1
redhat 3scale_api_management_platform 2.0
cisco iot_field_network_director *
apache tomcat *
f5 big-ip_carrier-grade_nat *
f5 big-ip_websafe 17.1.0
golang http2 *
redhat jboss_enterprise_application_platform 7.0.0
f5 big-ip_application_security_manager *
redhat migration_toolkit_for_containers -
microsoft windows_10_22h2 *
f5 big-ip_advanced_web_application_firewall *
apache solr *
redhat openshift_gitops -
f5 big-ip_carrier-grade_nat 17.1.0
kazu-yamamoto http2 *
redhat satellite 6.0
f5 big-ip_policy_enforcement_manager *
envoyproxy envoy 1.24.10
cisco prime_cable_provisioning *
redhat jboss_core_services -
f5 big-ip_webaccelerator *
f5 big-ip_next 20.0.1
cisco enterprise_chat_and_email -
f5 big-ip_advanced_firewall_manager 17.1.0
f5 big-ip_policy_enforcement_manager 17.1.0
nghttp2 nghttp2 *
istio istio *
f5 big-ip_ssl_orchestrator 17.1.0
redhat openshift_secondary_scheduler_operator -
redhat cost_management -
cisco expressway *
f5 big-ip_fraud_protection_service 17.1.0
golang go *
f5 big-ip_ssl_orchestrator *
f5 big-ip_analytics 17.1.0
f5 big-ip_global_traffic_manager *
cisco unified_contact_center_enterprise -
grpc grpc *
redhat cryostat 2.0
f5 big-ip_access_policy_manager 17.1.0
debian debian_linux 12.0
f5 big-ip_next_service_proxy_for_kubernetes *
redhat ceph_storage 5.0
traefik traefik 3.0.0
netty netty *
microsoft windows_11_22h2 *
f5 big-ip_application_security_manager 17.1.0
redhat node_healthcheck_operator -
f5 big-ip_application_visibility_and_reporting *