pantsel / konga

More than just another GUI to Kong Admin API

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2023-39792

AnduriCaser opened this issue · comments

I found an access control vulnerability in add new service section. Non-admin user can add new services without any permission.

I explained the details in the link below

https://docs.google.com/document/d/1UYEz1Kymr0_twJA0iwpEqacpLT2LuT8s7Bt3Ib9EJto/edit?usp=sharing