CVE Published: 27/12/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache APISIX Dashboard Status : PUBLISHED
CVE-2021-45232 Description
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.