QID 730047
Date Published: 2021-05-06
QID 730047: Kong Docker Image Weak Authentication Vulnerability
Kong is a scalable, open source API Platform (also known as an API Gateway or API Middleware).
Affected Versions:
Kong docker images before 1.0.2-alpine (Alpine specific)
QID Detection Logic:
This QID checks for the vulnerable version of Kong Docker.
System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Solution
Upgrade to the Kong docker 1.0.2 or to the latest version of Kong docker. Please refer to Kong docker Website.
Vendor References
- Kong Docker -
hub.docker.com/_/kong
CVEs related to QID 730047
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Kong Docker |
|