Privilege Escalation The advisory has been revoked - it doesn't affect any version of package konga  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.04% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-KONGA-2434821
  • published29 Mar 2022
  • disclosed29 Mar 2022
  • creditFabricio Salomao, Paulo Trindade

Introduced: 29 Mar 2022

CVE-2021-44103  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

There is no fixed version for konga.

Amendment

This was deemed not a vulnerability.

Overview

konga is an A boilerplate management utility for creating and reusing app templates. The default template is a Koa/Mongoose/AngularJS boilerplate. User-generated templates are not limited to any particular framework or library.

Affected versions of this package are vulnerable to Privilege Escalation when creating a new user, it is possible to change the admin parameter in the creation request from false to true, so an administrator user will be created.

Note: CVE-2021-44103 is a duplicate of CVE-2021-42192.

References