Lucene search

K
osvGoogleOSV:CVE-2021-45232
HistoryDec 27, 2021 - 3:15 p.m.

CVE-2021-45232

2021-12-2715:15:07
Google
osv.dev
7
apache apisix
dashboard
manager api
authentication
bypass
cve-2021-45232
framework
droplet
gin

AI Score

6.9

Confidence

Low

EPSS

0.971

Percentile

99.8%

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework droplet on the basis of framework gin, all APIs and authentication middleware are developed based on framework droplet, but some API directly use the interface of framework gin thus bypassing the authentication.

AI Score

6.9

Confidence

Low

EPSS

0.971

Percentile

99.8%