Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c538-784j-qcxc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

EPSS

Процентиль: 100%
0.93434
Критический

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 5 лет назад

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

EPSS

Процентиль: 100%
0.93434
Критический

6.5 Medium

CVSS3