pantsel/konga
Releases57
Frequency3 weeks 2 days
Last Release
Stars4.36K
More than just another GUI to Kong Admin API
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| = 0.14.9 | 5.4 MEDIUM | — | ||
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter. | ||||
| = 0.14.9 | 9.8 CRITICAL | — | ||
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token. | ||||
| = 0.14.9 | 6.5 MEDIUM | — | ||
An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request. | ||||
| = 0.14.9 | 8.8 HIGH | 9 HIGH | ||
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation. | ||||