Description
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.
No analysis available yet.
Remediation
Vendor Workaround
Implement one of the following mitigation techniques: 1. Upgrade to release 2.10.1 2. Change the default username and password, restrict the source IP to access the Apache APISIX Dashboard
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T04:39:20.275Z
Reserved: 2021-12-18T00:00:00.000Z
Link: CVE-2021-45232
No data.
Status : Modified
Published: 2021-12-27T15:15:07.757
Modified: 2024-11-21T06:32:01.333
Link: CVE-2021-45232
No data.
OpenCVE Enrichment
No data.
Weaknesses