当前位置:网站首页>Apache APIs IX has the risk of rewriting the x-real-ip header (cve-2022-24112)
Apache APIs IX has the risk of rewriting the x-real-ip header (cve-2022-24112)
2022-06-26 16:45:00 【Apacheapisik China Community】
Problem description
stay Apache APISIX 2.12.1 In the previous version ( It doesn't contain 2.12.1 and 2.10.4), Enable Apache APISIX batch-requests After the plug-in , There will be rewriting X-REAL-IP header risk .
This risk leads to two problems :
- Through
batch-requestsPlug ins bypass Apache APISIX Data plane IP Limit . For example, bypass IP Black and white list restrictions . - If the user uses Apache APISIX The default configuration ( Enable Admin API , Use the default Admin Key And no additional management ports are assigned ), Attackers can get through
batch-requestsPlug in call Admin API .
Affects version
- Apache APISIX 1.3 ~ 2.12.1 Between all versions ( It doesn't contain 2.12.1 )
- Apache APISIX 2.10.0 ~ 2.10.4 LTS Between all versions ( It doesn't contain 2.10.4)
Solution
- The problem has been solved in 2.12.1 and 2.10.4 Resolved in version , Please update to the relevant version as soon as possible .
- In the affected Apache APISIX In the version , It can be done to
conf/config.yamlandconf/config-default.yamlFile explicitly commented outbatch-requests, And restart Apache APISIX This risk can be avoided .
Vulnerability Details
Vulnerability priority : high
Vulnerability disclosure time :2022 year 2 month 11 Japan
CVE Details :https://nvd.nist.gov/vuln/detail/CVE-2022-24112
Contributor profile
The vulnerability was discovered by Changting technology in Real World CTF Found in , And by the Sauercloud Report to Apache Software foundation . Thank you for Apache APISIX Community contribution .

边栏推荐
- No manual prior is required! HKU & Tongji & lunarai & Kuangshi proposed self supervised visual representation learning based on semantic grouping, which significantly improved the tasks of target dete
- Greenplum database fault analysis - semop (id=2000421076, num=11) failed: invalid argument
- Calculate a=1, a2=1/1=a1
- [understanding of opportunity -31]: Guiguzi - Daoyu [x ī] Crisis is the coexistence of danger and opportunity
- JS tutorial - printing stickers / labels using the electronjs desktop application
- 基于STM32+华为云IOT设计的云平台监控系统
- [Li Kou brush question] monotone stack: 84 The largest rectangle in the histogram
- Teach you to learn dapr - 5 Status management
- What is the preferential account opening policy of securities companies now? Is it safe to open an account online now?
- [from deleting the database to running] the end of MySQL Foundation (the first step is to run.)
猜你喜欢

【毕业季】致毕业生的一句话:天高任鸟飞,海阔凭鱼跃

Développer un opérateur basé sur kubebuilder (démarrer)

Constructors and Destructors

国内首款开源 MySQL HTAP 数据库即将发布,三大看点提前告知

Stm32h7b0 replaces the h750 program, causing the MCU to hang up and unable to burn the program

Dialogue with the senior management of Chang'an Mazda, new products will be released in Q4, and space and intelligence will lead the Japanese system

Science | 红树林中发现的巨型细菌挑战传统无核膜观念

Set up your own website (16)

Make up the weakness - Open Source im project openim about initialization / login / friend interface document introduction

100+数据科学面试问题和答案总结 - 基础知识和数据分析
随机推荐
Toupper function
Exquisite makeup has become the "soft power" of camping, and the sales of vipshop outdoor beauty and skin care products have surged
基于STM32+华为云IOT设计的云平台监控系统
电路中缓存的几种形式
Memory partition model
Science | 红树林中发现的巨型细菌挑战传统无核膜观念
Binary array command of redis
Multiply the values of the upper triangular elements of the array by M
108. 简易聊天室11:实现客户端群聊
Fgetc() reads content from file
When a programmer is disturbed 10 times a day, the consequences are amazing!
进军AR领域,这一次罗永浩能成吗?
Cloud platform monitoring system based on stm32+ Huawei cloud IOT design
NFT 交易市场社区所有化势不可挡
TCP拥塞控制详解 | 1. 概述
MS | Xie Liwei group found that mixed probiotics and their metabolites could alleviate colitis
In a bad mood, I just write code like this
Knowing these commands allows you to master shell's own tools
【小5聊】毕业8年,一直在追梦的路上
Redis 迁移(操作流程建议)