CVE-2023-39846: Critical severity konga vulnerability
Published Aug 16, 2023
·Updated
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
Affected Software
1 affected component
Pantsel Konga=0.14.9
Event History
Aug 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue in Konga v0.14.9?
The vulnerability ID of this issue in Konga v0.14.9 is CVE-2023-39846.
2
What is the severity of CVE-2023-39846?
The severity of CVE-2023-39846 is critical with a CVSS score of 9.8.
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by bypassing authentication via a crafted JWT token.
4
Which software version is affected by vulnerability CVE-2023-39846?
Vulnerability CVE-2023-39846 affects the Konga version 0.14.9.
5
Is there a fix available for CVE-2023-39846?
At the moment, there is no information available about a fix for CVE-2023-39846. It is recommended to follow the official sources for updates and patches.