Executive brief
Apache APISIX contains a flaw in the batch-requests plugin that allows attackers to bypass IP restrictions and the Admin API authentication. This vulnerability can lead to remote code execution, particularly in default configurations where the admin key has not been changed.
Affected products
- Apache APISIX up to (excluding) 2.10.4, and 2.11.0 up to (excluding) 2.12.1
Timeline
- 2022-02-11: disclosed: Initial disclosure and NVD publication
- 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2022-02-11: advisory: Apache Software Foundation advisory published