Apisix Dashboard Apache Apisix Dashboard

Do you want an email whenever new security vulnerabilities are reported in Apache Apisix Dashboard?

By the Year

In 2024 there have been 0 vulnerabilities in Apache Apisix Dashboard . Apisix Dashboard did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 2 7.55
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Apisix Dashboard vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Apisix Dashboard Security Vulnerabilities

In Apache APISIX Dashboard before 2.10.1

CVE-2021-45232 9.8 - Critical - December 27, 2021

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.

Missing Authentication for Critical Function

In Apache APISIX Dashboard version 2.6

CVE-2021-33190 5.3 - Medium - June 08, 2021

In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to bypass the network limit. At the same time, the default account and password are fixed.Ultimately these factors lead to the issue of security risks. This issue is fixed in APISIX Dashboard 2.6.1

Improper Restriction of Excessive Authentication Attempts

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Apisix Dashboard or by Apache? Click the Watch button to subscribe.

Apache
Vendor

subscribe