Skip to content
COOEY

EXPOSURES › CVE-2022-24112

CVE-2022-24112

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-24112 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Apache APISIX RCE due to auth bypass actively exploited in wild

An Apache APISIX vulnerability allowed remote code execution due to an authentication bypass, which was actively exploited in the wild.

Shame score — Active exploitation in the wild indicates negligence and a failure to apply timely security patches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.