Apache APISIX 中存在一个安全决策中对不可信输入依赖的漏洞。 攻击者可以通过发送某些未由 插件正确进行处理的值,从而提升权限或绕过授权控制。 该漏洞影响 Apache APISIX 3.11.0 至 3.17.0 版本。 建议用户升级至 3.18.0 版本,该版本已修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 3.11.0≤ 3.17.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 3.11.0 ~ 3.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet