Lucene search

K
cvelistApacheCVELIST:CVE-2021-45232
HistoryDec 27, 2021 - 3:06 p.m.

CVE-2021-45232 security vulnerability on unauthorized access.

2021-12-2715:06:50
CWE-306
apache
www.cve.org
3
apache apisix dashboard
cve-2021-45232
unauthorized access
manager api
framework droplet
framework gin
authentication middleware

AI Score

9.8

Confidence

High

EPSS

0.971

Percentile

99.8%

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework droplet on the basis of framework gin, all APIs and authentication middleware are developed based on framework droplet, but some API directly use the interface of framework gin thus bypassing the authentication.

CNA Affected

[
  {
    "product": "Apache APISIX Dashboard",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "2.7 and 2.7.1"
      },
      {
        "status": "affected",
        "version": "2.8"
      },
      {
        "status": "affected",
        "version": "2.9"
      },
      {
        "status": "affected",
        "version": "2.10"
      }
    ]
  }
]

AI Score

9.8

Confidence

High

EPSS

0.971

Percentile

99.8%