Lucene search

K
f5F5F5:K31113511
HistoryJan 31, 2022 - 12:00 a.m.

K31113511 : Apache APISIX Dashboard vulnerability CVE-2021-45232

2022-01-3100:00:00
my.f5.com
30
apache apisix
dashboard
vulnerability

AI Score

9.6

Confidence

High

EPSS

0.971

Percentile

99.8%

Security Advisory Description

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework droplet on the basis of framework gin, all APIs and authentication middleware are developed based on framework droplet, but some API directly use the interface of framework gin thus bypassing the authentication. (CVE-2021-45232)

Impact

There is no impact; F5 products are not affected by this vulnerability.

AI Score

9.6

Confidence

High

EPSS

0.971

Percentile

99.8%