ZeroHour

CVE-2020-13945

PoC
CVSS 3.1
6.5 medium
EPSS
73%p99
Published
()
Modified
Description

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

Vendors
apache
Products
apisix
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.