CVE-2021-27306

Publication date

2021-03-18 14:02:16

Family

mitre

State

PUBLISHED

Description

An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.