security vulnerability on unauthorized access.
Published Dec 27, 2021
9.8
CRITICALCVSS 3.1
EPSS 86.33%
Description
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.
Affected products
-
Affected
- 2.10
- 2.7 and 2.7.1
- 2.8
- 2.9
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache APISIX Dashboard | unknown | Affected
|
- < 2.10.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Implement one of the following mitigation techniques:
1. Upgrade to release 2.10.1
2. Change the default username and password, restrict the source IP to access the Apache APISIX Dashboard
References (3)
- http://www.openwall.com/lists/oss-security/2021/12/27/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-32012 Advisory
- https://lists.apache.org/thread/979qbl6vlm8269fopfyygnxofgqyn6k5 x_refsource_MISCMailing ListVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2021/12/27/1 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-32012 | Advisory | |
| https://lists.apache.org/thread/979qbl6vlm8269fopfyygnxofgqyn6k5 | x_refsource_MISCMailing ListVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data