EXPOSURES › CVE-2022-24112
CVE-2022-24112
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
Apache APISIX RCE due to auth bypass actively exploited in wild
An Apache APISIX vulnerability allowed remote code execution due to an authentication bypass, which was actively exploited in the wild.
Shame score — Active exploitation in the wild indicates negligence and a failure to apply timely security patches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.