S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2020-11710 Scanner

CVE-2020-11710 scanner - Improper Access Control vulnerability in docker-compose template of Kong

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-11710
9.8
CVSS

An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself. In reality, this issue is not associated with any version of the Kong gateway. As such, the description stating ‘An issue was discovered in docker-kong (for Kong) through 2.0.3.’ is incorrect. This issue only occurs if a user decided to spin up Kong via docker-compose without following the security documentation. The docker-compose template is meant for users to quickly get started with Kong, and is meant for development purposes only. 2) Incorrect Patch Links - The CVE currently points to a documentation improvement as a “Patch” link: https://github.com/Kong/docs.konghq.com/commit/d693827c32144943a2f45abc017c1321b33ff611.This link actually points to an improvement Kong Inc made for fool-proofing. However, instructions for how to protect the admin API were already well-documented here: https://docs.konghq.com/2.0.x/secure-admin-api/#network-layer-access-restrictions , which was first published back in 2017 (as shown in this commit: https://github.com/Kong/docs.konghq.com/commit/e99cf875d875dd84fdb751079ac37882c9972949) Lastly, the hyperlink to https://github.com/Kong/kong (an unrelated Github Repo to this issue) on the Hyperlink list does not include any meaningful information on this topic.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Kong is a widely-used open-source API gateway that is used by enterprises to manage, secure, and extend APIs. To help developers get started quickly with Kong, the platform offers a docker-compose template that simplifies the process of setting up Kong on a local development environment. The docker-compose template is meant for users who want to quickly experiment and try out Kong as part of the development process. 

Recently, a vulnerability was discovered in Kong's docker-compose template that could potentially enable attackers to gain access to the admin API port through interfaces other than 127.0.0.1. The vulnerability code is CVE-2020-11710. The vendor, however, contests the CVE, stating that it is not a vulnerability. According to the vendor, the issue is related to the docker-compose template of Kong and not the Kong gateway image itself. The vendor also claims that the instructions to protect the admin API were already documented back in 2017, rendering the CVE irrelevant.

If the CVE is truly a vulnerability, then attackers can potentially gain unauthorized access to the admin API port, allowing them to manipulate and control the exposed endpoints. This could lead to malicious activities such as the modification of API settings, exposure of sensitive data, tampering with the gateway security settings, and more. Worst of all, businesses could experience severe financial and reputational damage due to the misuse of their APIs.

Overall, thanks to the pro features of the s4e.io platform, businesses can quickly and easily identify any vulnerabilities in their digital assets, including Kong. The platform continuously monitors and scans for any potential threats, allowing businesses to take preemptive actions before it's too late. By staying vigilant and proactive, businesses can ensure that their APIs remain secure and protected from any malicious attacks.

 

REFERENCES

Solution Advice

To protect against the vulnerability, users can follow the security documentation provided by Kong, which involves implementing network-layer access restrictions. Here are some precautions that can be taken to protect against the vulnerability:

  • Restrict admin API access only to authorized users.
  • Limit the scope of the admin API to only allow access via the localhost.
  • Ensure that Kong is up-to-date with the latest patches and security updates.
  • Implement multi-factor authentication for the admin API to prevent unauthorized access.
  • Regularly review and monitor Kong logs for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.