CVE Published: 07/12/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache APISIX Status : PUBLISHED
CVE-2020-13945 Description
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.