In Apache APISIX Dashboard before 2.10.1, the Manager API...
Critical severity
Unreviewed
Published
Dec 28, 2021
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Dec 27, 2021
Published to the GitHub Advisory Database
Dec 28, 2021
Last updated
Feb 3, 2023
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework
droplet
on the basis of frameworkgin
, all APIs and authentication middleware are developed based on frameworkdroplet
, but some API directly use the interface of frameworkgin
thus bypassing the authentication.References