CVE-2021-45232

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
27/12/2021
Last modified:
07/01/2022

Description

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:apisix_dashboard:*:*:*:*:*:*:*:* 2.10.1 (excluding)