First published: Sat Apr 29 2023(Updated: )
A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The associated identifier of this vulnerability is VDB-227715.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Konghq Kong | =2.8.3 | |
=2.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2418 is medium.
The affected software for CVE-2023-2418 is Kong 2.8.3.
The CWE ID for CVE-2023-2418 is 330.
There is no specific fix available yet for CVE-2023-2418. It is recommended to follow the official advisory and monitor for any updates or patches from the vendor.
You can find more information about CVE-2023-2418 in the following references: [GitHub Advisory](https://github.com/advisories/GHSA-9g4c-xm3g-f8hq), [VulDB](https://vuldb.com/?ctiid.227715), [VulDB](https://vuldb.com/?id.227715).