CVE-2021-42192: Critical severity kong vulnerability
Published May 4, 2022
·Updated
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.
Affected Software
1 affected component
Konga Project Konga=0.14.9
Event History
May 4, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-42192?
CVE-2021-42192 is classified as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2021-42192?
To mitigate CVE-2021-42192, upgrade Konga to a version higher than 0.14.9 that addresses the access control vulnerability.
3
What systems are affected by CVE-2021-42192?
CVE-2021-42192 specifically affects Konga version 0.14.9.
4
What type of vulnerability is CVE-2021-42192?
CVE-2021-42192 is an incorrect access control vulnerability.
5
Can CVE-2021-42192 lead to data breaches?
Yes, CVE-2021-42192 can lead to unauthorized access and potential data breaches through privilege escalation.