No analysis available yet.
Vendor Workaround
1. Upgrade to 2.13.1 and above 2. Apply the following patch to Apache APISIX and rebuild it: This will make this error message no longer contain sensitive information and return a fixed error message to the caller. For the current LTS 2.13.x or master: https://github.com/apache/apisix/pull/6846 https://github.com/apache/apisix/pull/6847 https://github.com/apache/apisix/pull/6858 For the last LTS 2.10.x: https://github.com/apache/apisix/pull/6847 https://github.com/apache/apisix/pull/6855 3. Manually modify the version you are using according to the commit above and rebuild it to circumvent the vulnerability.
Tracking
Sign in to view the affected projects.
No advisories yet.
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T06:17:54.494Z
Reserved: 2022-04-15T00:00:00.000Z
Link: CVE-2022-29266
No data.
Status : Modified
Published: 2022-04-20T08:15:07.740
Modified: 2024-11-21T06:58:50.163
Link: CVE-2022-29266
No data.
OpenCVE Enrichment
No data.