#VU59095 Improper Authentication in Apache APISIX - CVE-2021-45232
Published: December 27, 2021 / Updated: September 4, 2022
Apache APISIX
Apache Foundation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the Manager API. A remote attacker can bypass authentication process and gain unauthorized access to the application via certain API endpoints, that use directly "gin" framework instead of "droplet" framework.