CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It affects Apache.
CVE
CVE-2021-33190
Severity
MEDIUM
CVSS
5.3
EPSS
2.69%
Apache
Original NVD Description
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to bypass the network limit. At the same time, the default account and password are fixed.Ultimately these factors lead to the issue of security risks. This issue is fixed in APISIX Dashboard 2.6.1
Related CVEs
Other vulnerabilities affecting the same vendor(s)