Code Injection in Apache APISIX - CVE-2022-24112
Published: February 14, 2022 / Updated: June 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to an IP restriction of Admin API bypass flaw. A remote attacker can send a specially crafted request using the batch-requests plugin and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2022-24112
Links to Public Exploits and PoC-codes
- Exploit #9941 - exploit_CVE-2022-24112 (New exploit for Apache APISIX v2.12.1 - Remote code execution (RCE)) (June 7, 2024)
- Exploit #8642 - CVE-2022-24112_POC (CVE-2022-24112_POC) (December 4, 2022)
- Exploit #7813 - Apache APISIX 2.12.1 - Remote Code Execution (RCE) (May 13, 2022)
- Exploit #7777 - APISIX Admin API default access token RCE (May 12, 2022)
- Exploit #7519 - CVE-2022-24112-POC (Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token) (March 17, 2022)
- Exploit #7510 - Apache-APISIX-CVE-2022-24112 (Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit ) (March 17, 2022)
- Exploit #7460 - CVE-2022-24112 (CVE-2022-24112: Apache APISIX Remote Code Execution Vulnerability) (March 9, 2022)
- Exploit #7447 - CVE-2022-244112 (CVE-2022-24112: Apache APISIX Remote Code Execution Vulnerability) (March 8, 2022)
- Exploit #7398 - CVE-2022-24112 (Apache APISIX batch-requests RCE(CVE-2022-24112)) (February 27, 2022)
- Exploit #7373 - CVE-2022-24112 (CVE-2022-24112:Apache APISIX apisix/batch-requests RCE) (February 22, 2022)
- Exploit #7372 - CVE-2022-24112 (Apache APISIX apisix/batch-requests RCE) (February 22, 2022)
- Exploit #7365 - CVE-2022-24112 (CVE-2022-24112 check) (February 21, 2022)