apache apisix CVE-2022-29266 is a vulnerability in Apache Apisix
Published on April 20, 2022

apisix/jwt-auth may leak secrets in error response
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.

NVD

Weakness Type

Generation of Error Message Containing Sensitive Information

The software generates an error message that includes sensitive information about its environment, users, or associated data.


Products Associated with CVE-2022-29266

Want to know whenever a new CVE is published for Apache Apisix? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache APISIX:

Exploit Probability

EPSS
36.45%
Percentile
97.05%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.