CVE-2020-13945
MEDIUM 6.5EPSS 73.0%
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 4.0 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N - EPSS
- 72.98% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- medium · CWE-522
- Published
- 2020-12-07
- Updated
- 2024-08-04
Proof-of-concept exploits (3)
- http://packetstormsecurity.com/files/166228/Apache-APISIX-Remote-Code-Execution.html
- K3ysTr0K3R/CVE-2020-13945-EXPLOIT12★ · 2024-07-21
- samurai411/toolbox1★ · 2024-05-10