CVE-2022-1561
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests.
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend might be vulnerable.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-471
- Affected
- krakend/krakend · luraproject/lura
- Source
- cve-coordination@incibe.es
References
- https://www.incibe-cert.es/en/early-warning/security-advisories/crafted-backend-urls-lura-projectThird Party Advisory
- https://www.krakend.io/blog/cve-2022-1561-crafted-backend-urls/Vendor Advisory
- https://www.incibe-cert.es/en/early-warning/security-advisories/crafted-backend-urls-lura-projectThird Party Advisory
- https://www.krakend.io/blog/cve-2022-1561-crafted-backend-urls/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.