CVE-2022-24112 Details
Description
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
An authentication bypass vulnerability has been identified in the batch-requests plugin of Apache APISIX, allowing attackers to bypass IP restrictions on the Admin API. This vulnerability is present in versions 1.3 through 2.12.1. In a default configuration with the default API key, this flaw can be exploited to achieve remote code execution. Although changing the admin key or the Admin API port can reduce the impact, there remains a risk of bypassing IP restrictions on the data panel. The vulnerability arises because the batch-requests plugin is supposed to override the client IP with the real remote IP, but a bug allows this check to be bypassed.
Users are advised to update Apache APISIX to version 2.10.4 or 2.12.1, or to disable the batch-requests plugin in the configuration file.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apache APISIX Authentication Bypass Vulnerability | Aug 25, 2022 | Sep 15, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache apisix | < 2.10.4 >= 2.11.0, < 2.12.1 |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 23, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 6, 2025 | Modified Analysis | [email protected] |
| Jan 29, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 11, 2022 | Modified Analysis | [email protected] |
| Mar 16, 2022 | CVE Modified | [email protected] |
| Mar 10, 2022 | CVE Modified | [email protected] |
| Feb 18, 2022 | Initial Analysis | [email protected] |
| Feb 11, 2022 | CVE Modified | [email protected] |