Lucene search

K
osvGoogleOSV:CVE-2020-13945
HistoryDec 07, 2020 - 8:15 p.m.

CVE-2020-13945

2020-12-0720:15:12
Google
osv.dev
9
apache apisix
admin api
ip restriction
access token
security
cve-2020-13945

AI Score

6.7

Confidence

Low

EPSS

0.009

Percentile

83.0%

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

AI Score

6.7

Confidence

Low

EPSS

0.009

Percentile

83.0%