Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit
Summary An attacker can abuse the batch-requests plugin to send requests tobypass the IP restriction of Admin API.A default configuration of Apache APISIX (with default API key) isvulnerable to remote code execution.When the admin key was changed or the port of Admin API was changed toa port different from the data panel, the impact is lower. But thereis still a risk to bypass the IP restriction of Apache APISIX’s datapanel. There is a check in the batch-requests plugin which overrides […]
Read more