CVE-2021-27306: High severity kong vulnerability
Published Mar 18, 2021
·Updated
An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.
Affected Software
1 affected component
konghq Kong Gateway<2.3.2.0
Remediation
Event History
Mar 18, 2021
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
Description
Frequently Asked Questions
1
What is CVE-2021-27306?
CVE-2021-27306 is an improper access control vulnerability in the JWT plugin in Kong Gateway prior to version 2.3.2.0.
2
How does CVE-2021-27306 impact Kong Gateway?
CVE-2021-27306 allows unauthenticated users to access authenticated routes in Kong Gateway without a valid JWT token.
3
What is the severity of CVE-2021-27306?
CVE-2021-27306 has a severity rating of 7.5 (high).
4
Which version of Kong Gateway is affected by CVE-2021-27306?
CVE-2021-27306 affects Kong Gateway prior to version 2.3.2.0.
5
How can I fix CVE-2021-27306?
To fix CVE-2021-27306, upgrade to Kong Gateway version 2.3.2.0 or later.