CVE-2022-24112
Last modified
CVE-2022-24112 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. CISA has confirmed active exploitation in the wild. EPSS estimates a 96.18% chance of exploitation in the next 30 days.
Description
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Apisix | < 2.10.4 |
| Apache | Apisix | >= 2.11.0, < 2.12.1 |
References
- https://packetstormsecurity.com/files/166228/Apache-APISIX-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/166328/Apache-APISIX-2.12.1-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2022/02/11/3Mailing List, Mitigation, Third Party Advisory
- https://lists.apache.org/thread/lcdqywz8zy94mdysk7p3gfdgn51jmt94Mailing List, Mitigation, Vendor Advisory
- https://packetstormsecurity.com/files/166228/Apache-APISIX-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/166328/Apache-APISIX-2.12.1-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2022/02/11/3Mailing List, Mitigation, Third Party Advisory
- https://lists.apache.org/thread/lcdqywz8zy94mdysk7p3gfdgn51jmt94Mailing List, Mitigation, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24112Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-24112?
How severe is CVE-2022-24112?
How do I fix CVE-2022-24112?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-24107Xpdf prior to 4.04 lacked an integer overflow check in JPXSt…7.8
- CVE-2022-24108The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allo…9.8
- CVE-2022-24109An issue was discovered in ONOS 2.5.1. To attack an intent i…6.5
- CVE-2022-2411The Auto More Tag WordPress plugin through 4.0.0 does not sa…4.8
- CVE-2022-24110Kiteworks MFT 7.5 may allow an unauthorized user to reset ot…6.5
- CVE-2022-24111In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, por…5.3
- CVE-2022-24113Local privilege escalation due to excessive permissions assi…7.8
- CVE-2022-24114Local privilege escalation due to race condition on applicat…7
- CVE-2022-24115Local privilege escalation due to unrestricted loading of un…7.8
- CVE-2022-24116Certain General Electric Renewable Energy products have inad…9.8
- CVE-2022-24117Certain General Electric Renewable Energy products download …9.8
- CVE-2022-24118Certain General Electric Renewable Energy products allow att…9.1
Are you affected by CVE-2022-24112?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
