Apache APISIX Remote Code Execution
Posted by deepcore on March 8, 2022 – 7:01 pm
Apache APISIX has a default, built-in API token that can be used to obtain full access of the admin API. Access to this API allows for remote LUA code execution through the script parameter added in the 2.x version. This module also leverages another vulnerability to bypass th e IP restriction plugin.
Post a reply
You must be logged in to post a comment.