CVE-2022-24112
KEVCRITICAL 9.8EPSS 96.0%
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 96.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-08-25
- Nuclei
- critical · CWE-290
- Published
- 2022-02-11
- Updated
- 2025-10-21
Proof-of-concept exploits (15)
- http://packetstormsecurity.com/files/166228/Apache-APISIX-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/166328/Apache-APISIX-2.12.1-Remote-Code-Execution.ht…
- Acczdy/CVE-2022-24112_POC5★ · 2022-12-04
- Axx8/CVE-2022-241128★ · 2022-02-25
- CrackerCat/CVE-2022-241120★ · 2022-02-22
- M4xSec/Apache-APISIX-CVE-2022-2411215★ · 2022-03-16
- Mah1ndra/CVE-2022-241127★ · 2022-03-08
- Mah1ndra/CVE-2022-2441127★ · 2022-03-08
- Mr-xn/CVE-2022-2411243★ · 2022-02-22
- SecNN/CVE-2022-241128★ · 2022-02-25
- btar1gan/exploit_CVE-2022-241121★ · 2024-06-07
- fatkz/CVE-2022-241120★ · 2025-05-23
- kavishkagihan/CVE-2022-24112-POC2★ · 2022-03-17
- twseptian/cve-2022-241129★ · 2022-03-20
- 34zY/APT-Backpack