Kong Event Gateway是Kong公司的一款事件网关。 Kong Event Gateway 1.0.0至1.1.1版本和1.2.0版本存在加密问题漏洞,该漏洞源于在启用AWS IAM加密功能时,未在达到NIST SP 800-38D推荐的AES-GCM加密密钥随机nonce使用限制前强制密钥轮换,可能导致nonce碰撞,进而允许授权消费者恢复受影响消息的部分明文。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kong | Kong Event Gateway | 1.0.0< 1.1.2 |
affected |
1.2.0< 1.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kong | Kong Event Gateway | 1.0.0 ~ 1.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet