Vulnerabilities > TYK

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-42283 SQL Injection vulnerability in TYK 5.0.3
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
network
low complexity
tyk CWE-89
critical
9.8
2023-11-07 CVE-2023-42284 SQL Injection vulnerability in TYK 5.0.3
Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
network
low complexity
tyk CWE-89
critical
9.8
2021-04-26 CVE-2021-23365 Improper Authentication vulnerability in TYK Tyk-Identity-Broker
The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass.
network
low complexity
tyk CWE-287
critical
9.1
2021-03-15 CVE-2021-23357 Path Traversal vulnerability in TYK
All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOrUpdateApi function.
local
low complexity
tyk CWE-22
5.3