Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-12799
HistoryFeb 15, 2022 - 12:00 a.m.

Apache Apisix Remote Code Execution Vulnerability

2022-02-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
101
apache apisix
remote code execution
vulnerability
batch-requests plugin
ip restrictions
apache foundation
cloud-native
microservices
cnvd

EPSS

0.974

Percentile

99.9%

Apache Apisix is a cloud-native microservices API gateway service from the Apache Foundation. A remote code execution vulnerability exists in Apache APISIX, which stems from the productโ€™s batch-requests plugin not effectively limiting batch requests to users. An attacker could bypass the Admin APIโ€™s IP restrictions through this vulnerability, which could easily lead to remote code execution.