Developer Tools & Libraries

Authentication & Access Bypass

Privilege Escalation in Konga v0.14.9

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

8.8
/ 10
High
CVSS v3.1
ADVISORY ID
PS53
PUBLISHED
2022-10-05
CVE IDs
CVE-2021-42192
VENDORS
Konga
PUBLIC EXPLOIT
PoC public
CWE
CWE-863
PRODUCT
Konga v0.14.9
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

The latest release of Konga, i.e., Konga v0.14.9, has a privilege escalation vulnerability which allows normal users to gain admin privileges.

Vulnerability details

Vulnerability details

CVE-2021-42192
CWE-863
High | 8.8

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

Auth:
Any authenticated user (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2021-10-16 Reported On

2022-05-04 Made Public On

Fixed On

References

Credits

Debjeet Banerjee