Junglewise Threat Intelligence

CVE-2024-34243: Konga stored XSS in username parameter

CVE-2024-34243 · Severity: low · CVSS 3.1 · Published 2024-05-14

Vendors: npm.

Executive brief

Konga is an open-source admin UI for Kong API Gateway. The application fails to properly sanitize user input in the username field, allowing attackers to inject malicious JavaScript code. When an administrator views or deletes a user account, the injected script executes in their browser, potentially enabling account takeover, session theft, or manipulation of gateway configuration.

Technical details

Konga v0.14.9 contains a stored Cross-Site Scripting (XSS) vulnerability in the username field (CWE-79). The vulnerability arises from insufficient input validation and output encoding when processing user account data. An attacker can create or modify a user account with JavaScript code embedded in the username parameter; the malicious script executes when an administrator interacts with that user (e.g., viewing or deleting the user account). The attack requires network access but no authentication to create a malicious account in some configurations. Exploitation allows script execution in an admin's browser context, potentially leading to credential theft, session hijacking, or unauthorized API Gateway reconfiguration.

Affected products

  • Konga Konga 0.14.9 and earlier

Timeline

  • 2024-05-14: disclosed
  • 2024-05-14: advisory

References