Record summary

CVE-2022-1561 has a selected CVSS score of 4.0 (medium).

Description

Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend might be vulnerable.

Description source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE Listv2.0.2 to < v2.0.2affected
CVE Listv2.0.0 to < v2.0.0affected
CVE Listv2.0.2 to < v2.0.2affected

References

3