Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Crafted backend URLs in Lura Project
Vulnerability Description
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend might be vulnerable.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Vulnerability Type
对假设不可变数据的修改(MAID)
Vulnerability Title
Lura和KrakenD 安全漏洞
Vulnerability Description
Lura是Lura Project开源的一个将超高性能 API 网关与中间件组装在一起的开放框架。KrakenD是KrakenD开源的一个可扩展的超高性能 API 网关。可帮助您轻松采用微服务和安全通信。 Lura 和 KrakenD-CE 2.0.2 之前版本和 KrakenD-EE 2.0.0 之前版本存在安全漏洞,该漏洞源于不正确清理 URL 参数,当远程用户发送狡猾的 URL 请求时,允许恶意用户更改为管道定义的后端 URL。该漏洞不会影响 KrakenD 本身,但使用的后端可能容易受到攻击。
CVSS Information
N/A
Vulnerability Type
N/A