CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2022-24112

CVSS 9.8v3.1pub. 2022-02-11upd. 2025-10-23

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Apisix

    APP
    Apache
    < 2.10.42.11.0 – 2.12.1 (excl.)

CISA KEV — detailsi

Vendori
Apache
Producti
APISIX
Added to KEVi
August 25, 2022
Remediation deadline (US Federal)i
September 15, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 15 września 2022
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-31908CRITICAL9.1PL ✓same product

Header injection w pluginie forward-auth Apache APISIX

CVE-2022-25757CRITICAL9.8PL ✓same product

Apache APISIX — pominięcie walidacji body_schema przez duplikaty kluczy JSON

CVE-2026-74848HIGH7.0same product

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISI...

CVE-2026-75005HIGH8.7same product

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway ...

CVE-2026-75020HIGH7.0same product

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache A...