CVE-2023-2418: Konga Login API random values
A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The associated identifier of this vulnerability is VDB-227715.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2418?
The severity of CVE-2023-2418 is medium.
What is the affected software for CVE-2023-2418?
The affected software for CVE-2023-2418 is Kong 2.8.3.
What is the CWE ID for CVE-2023-2418?
The CWE ID for CVE-2023-2418 is 330.
How can I fix CVE-2023-2418?
There is no specific fix available yet for CVE-2023-2418. It is recommended to follow the official advisory and monitor for any updates or patches from the vendor.
Where can I find more information about CVE-2023-2418?
You can find more information about CVE-2023-2418 in the following references: [GitHub Advisory](https://github.com/advisories/GHSA-9g4c-xm3g-f8hq), [VulDB](https://vuldb.com/?ctiid.227715), [VulDB](https://vuldb.com/?id.227715).