Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend might be vulnerable.

Project Subscriptions

Vendors Products
Krakend Subscribe
Krakend Subscribe
Luraproject Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-24853 Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend might be vulnerable.
Fixes

Solution

Lura Project and KrakenD-CE users must upgrade to v2.0.2 or higher. KrakenD-EE users must upgrade to v2.0.0 or higher.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-17T02:16:30.060Z

Reserved: 2022-05-03T00:00:00

Link: CVE-2022-1561

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-01T13:15:09.810

Modified: 2024-11-21T06:40:58.340

Link: CVE-2022-1561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses