AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-33190

MEDIUM · CVSS 5.3 EPSS 2.69%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-06-08 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. It affects Apache.

CVE
CVE-2021-33190
Severity
MEDIUM
CVSS
5.3
EPSS
2.69%
Apache

Original NVD Description

In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to bypass the network limit. At the same time, the default account and password are fixed.Ultimately these factors lead to the issue of security risks. This issue is fixed in APISIX Dashboard 2.6.1

Related CVEs

Other vulnerabilities affecting the same vendor(s)