CVE-2020-11710 describes an issue where the Kong Admin API port might be exposed on interfaces other than 127.0.0.1 when using docker-kong through version 2.0.3. This vulnerability is rated Critical with a CVSS score of 9.8, indicating a network-exploitable flaw with low attack complexity that could lead to complete compromise of confidentiality, integrity, and availability. While the vendor disputes this as a true vulnerability, arguing it stems from misconfiguration of a development-focused docker-compose template rather than a flaw in Kong itself, Nuclei templates exist for detecting this misconfiguration. There is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.3CPE matchmatch criteria | cpe:2.3:a:konghq:docker-kong:*:*:*:*:*:kong:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.