
We found results for “”
CVE-2021-45232
Date: December 27, 2021
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework "droplet" on the basis of framework "gin", all APIs and authentication middleware are developed based on framework "droplet", but some API directly use the interface of framework "gin" thus bypassing the authentication.
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
Missing Authentication for Critical Function
CWE-306CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |