CVE-2022-1561
Published: Aug 1, 2022
Modified: Sep 17, 2024
CVSS v3.1
4.0
Description
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend might be vulnerable.
| Vendor | Product | Versions |
|---|---|---|
KrakenD | Lura Project | affected v2.0.2 - < v2.0.2 |
KrakenD | KrakenD-CE | affected v2.0.2 - < v2.0.2 |
KrakenD | KrakenD-EE | affected v2.0.0 - < v2.0.0 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now