Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Apisix
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13945 1 Apache 1 Apisix 2020-12-08 4.0 MEDIUM 6.5 MEDIUM
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.