pantsel/konga

pantsel/konga

Releases57
Frequency3 weeks 2 days
Last Release
Stars4.36K
More than just another GUI to Kong Admin API

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 0.14.95.4 MEDIUM

Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.

= 0.14.99.8 CRITICAL

An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.

= 0.14.96.5 MEDIUM

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

= 0.14.98.8 HIGH9 HIGH

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.