Back

CRITICAL

security vulnerability on unauthorized access.

Published Dec 27, 2021

Description

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.

Affected products

Remediation

Vendor solution

Implement one of the following mitigation techniques:

1. Upgrade to release 2.10.1

2. Change the default username and password, restrict the source IP to access the Apache APISIX Dashboard

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Dec 27, 2021
Updated Aug 4, 2024
Reserved Dec 18, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner apache
Published Dec 27, 2021
Updated Aug 4, 2024

GitHub

No data