In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Implement one of the following mitigation techniques: 1. Upgrade to release 2.10.1 2. Change the default username and password, restrict the source IP to access the Apache APISIX Dashboard
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T04:39:20.275Z
Reserved: 2021-12-18T00:00:00
Link: CVE-2021-45232
No data.
Status : Modified
Published: 2021-12-27T15:15:07.757
Modified: 2024-11-21T06:32:01.333
Link: CVE-2021-45232
No data.
OpenCVE Enrichment
No data.
Weaknesses