peter bassill · operator
$ cve CVE-2022-24112 JSON

CVE-2022-24112 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 96.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-09-15.

Description

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS96.07% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-290
On CISA KEVyes — remediate by 2022-09-15
Public exploityes
Published2022-02-11
Last modified2026-06-17

CISA KEV

NameApache APISIX Authentication Bypass Vulnerability
Added2022-08-25
Due2022-09-15
Vendor / productApache / APISIX
Ransomware usenone reported

Affected (1)

VendorProduct
apacheapisix

Public exploits

SourceTitleDate
exploit-dbApache APISIX 2.12.1 - Remote Code Execution (RCE)2022-03-16

References

→ the Explorer  ·  watch your stack  ·  NVD