In Apache APISIX Dashboard before 2.10.1, the Manager API...
Critical severity
Unreviewed
Published
Dec 28, 2021
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Dec 27, 2021
Published to the GitHub Advisory Database
Dec 28, 2021
Last updated
Feb 3, 2023
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework
dropleton the basis of frameworkgin, all APIs and authentication middleware are developed based on frameworkdroplet, but some API directly use the interface of frameworkginthus bypassing the authentication.References