当前位置:网站首页>Apache APIs IX has the risk of rewriting the x-real-ip header (cve-2022-24112)
Apache APIs IX has the risk of rewriting the x-real-ip header (cve-2022-24112)
2022-06-26 16:45:00 【Apacheapisik China Community】
Problem description
stay Apache APISIX 2.12.1 In the previous version ( It doesn't contain 2.12.1 and 2.10.4), Enable Apache APISIX batch-requests After the plug-in , There will be rewriting X-REAL-IP header risk .
This risk leads to two problems :
- Through
batch-requestsPlug ins bypass Apache APISIX Data plane IP Limit . For example, bypass IP Black and white list restrictions . - If the user uses Apache APISIX The default configuration ( Enable Admin API , Use the default Admin Key And no additional management ports are assigned ), Attackers can get through
batch-requestsPlug in call Admin API .
Affects version
- Apache APISIX 1.3 ~ 2.12.1 Between all versions ( It doesn't contain 2.12.1 )
- Apache APISIX 2.10.0 ~ 2.10.4 LTS Between all versions ( It doesn't contain 2.10.4)
Solution
- The problem has been solved in 2.12.1 and 2.10.4 Resolved in version , Please update to the relevant version as soon as possible .
- In the affected Apache APISIX In the version , It can be done to
conf/config.yamlandconf/config-default.yamlFile explicitly commented outbatch-requests, And restart Apache APISIX This risk can be avoided .
Vulnerability Details
Vulnerability priority : high
Vulnerability disclosure time :2022 year 2 month 11 Japan
CVE Details :https://nvd.nist.gov/vuln/detail/CVE-2022-24112
Contributor profile
The vulnerability was discovered by Changting technology in Real World CTF Found in , And by the Sauercloud Report to Apache Software foundation . Thank you for Apache APISIX Community contribution .

边栏推荐
- Swap two numbers
- [207] several possible causes of Apache crash
- 基於Kubebuilder開發Operator(入門使用)
- Cuckoo filter for Chang'an chain transaction
- day10每日3题(1):逐步求和得到正数的最小值
- Multiply the values of the upper triangular elements of the array by M
- Solution for filtering by special string of microservice
- Research on natural transition dubbing processing scheme based on MATLAB
- Vibrating liquid quantity detecting device
- 探讨:下一代稳定币
猜你喜欢
![[understanding of opportunity -31]: Guiguzi - Daoyu [x ī] Crisis is the coexistence of danger and opportunity](/img/e8/9c5f1658a252c3c80503b5021917f6.jpg)
[understanding of opportunity -31]: Guiguzi - Daoyu [x ī] Crisis is the coexistence of danger and opportunity

经典同步问题

GUI+SQLServer考试系统

IAR engineering adapts gd32 chip

C语言 头哥习题答案截图

How to implement interface current limiting?

MS | Xie Liwei group found that mixed probiotics and their metabolites could alleviate colitis
![[force deduction question] two point search: 4 Find the median of two positive arrays](/img/4f/43aa7e14344e7e1a2fb7c1d209d13b.png)
[force deduction question] two point search: 4 Find the median of two positive arrays

架构实战营毕业设计

The first open source MySQL HTAP database in China will be released soon, and the three highlights will be notified in advance
随机推荐
JUnit unit test
《软件工程》期末重点复习笔记
Redis overview
MS|谢黎炜组发现混合益生菌制剂及其代谢产物可缓解结肠炎
JS tutorial using electron JS build native desktop application ping pong game
Science | 红树林中发现的巨型细菌挑战传统无核膜观念
牛客编程题--必刷101之动态规划(一文彻底了解动态规划)
【从删库到跑路】JDBC 完结篇(一天学完系列!!学完赶紧跑!)
TCP拥塞控制详解 | 1. 概述
Least squares system identification class II: recursive least squares
[graduation season] a word for graduates: the sky is high enough for birds to fly, and the sea is wide enough for fish to leap
Day10 daily 3 questions (3): String Matching in array
108. 简易聊天室11:实现客户端群聊
Learn about common functional interfaces
[Li Kou brush questions] 11 Container holding the most water //42 Rain water connection
Leetcode 1170. 比较字符串最小字母出现频次(可以,已解决)
【MATLAB项目实战】基于卷积神经网络与双向长短时(CNN-LSTM)融合的锂离子电池剩余使用寿命预测
LeetCode Algorithm 24. 两两交换链表中的节点
STM32F103C8T6实现呼吸灯代码
In a bad mood, I just write code like this