Apache APISIX < 2.13.1 Information Disclosure
Discription
The version of Apache APISIX installed on the remote host is prior to 2.13.1. It is, therefore, potentially affected by an information disclosure vulnerability because the jwt-auth plugin has a security issue that leaks the user’s secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.
Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.Read More
References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29266https://github.com/apache/apisix/blob/release/2.13/CHANGELOG.md#2131https://lists.apache.org/thread/6qpfyxogbvn18g9xr8g218jjfjbfsbhrBack to Main