Kong records
2 published records for vendor kong.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-35189No exploit | The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user.kong · kong alpine docker image · CWE-306 | Critical9.8 | — | 2.2% | Dec 16, 2020 |
17Monitor | CVE-2012-6572No exploit | Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1kong · inf08 · CWE-79 | Medium4.3 | — | 1.3% | Jun 21, 2013 |
- CVE-2020-3518940Plan
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%kong · kong alpine docker imageDec 16, 2020
- CVE-2012-657217Monitor
Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1
MediumCVSS 4.3No exploitEPSS 1%kong · inf08Jun 21, 2013