Vulnerabilities
Vulnerable Software
Konghq:  >> Kong Gateway  >> 1.5.0.7  Security Vulnerabilities
CVE-2023-44487
Known exploited
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVSS Score
7.5
EPSS Score
0.944
Published
2023-10-10
An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.
CVSS Score
7.5
EPSS Score
0.015
Published
2021-03-18


Contact Us

Shodan ® - All rights reserved