CVE-2020-13945

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/12/2020
Last modified:
19/04/2022

Description

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*:* 1.2 (including) 1.5 (including)