Impact
The data‑mask filter in Apache APISIX fails to redact certain request headers, allowing those header values to be written to log files when a specific response structure is used. This flaw can expose confidential information to anyone with access to the logs, thereby compromising confidentiality.
Affected Systems
Apache Software Foundation Apache APISIX version 3.17.0 is affected by this vulnerability.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity, and the EPSS score is not available while the issue is not listed in CISA's KEV catalog. The flaw requires that an attacker generate requests that trigger the vulnerable logging path; if the resulting logs are accessible, the attacker can read sensitive header contents. The risk is highest when logs are stored in insecure locations or are readable by privileged users with improper access controls.
OpenCVE Enrichment