Junglewise Threat Intelligence

CVE-2022-24112: Apache APISIX Authentication Bypass Vulnerability

CVE-2022-24112 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-08-25

Technologies: Apache APISIX. Vendors: Apache.

Executive brief

Apache APISIX contains a flaw in the batch-requests plugin that allows attackers to bypass IP restrictions and the Admin API authentication. This vulnerability can lead to remote code execution, particularly in default configurations where the admin key has not been changed.

Affected products

  • Apache APISIX up to (excluding) 2.10.4, and 2.11.0 up to (excluding) 2.12.1

Timeline

  • 2022-02-11: disclosed: Initial disclosure and NVD publication
  • 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2022-02-11: advisory: Apache Software Foundation advisory published

Related threats