CyberRota Analysis
AI-GeneratedApache APISIX versions 3.11.0 through 3.17.0 are vulnerable to a privilege escalation and authorization bypass due to improper sanitization of untrusted inputs in the attach-consumer-label plugin. This could allow attackers to manipulate security decisions, potentially compromising the integrity of the system. Organizations using affected versions should prioritize upgrading to version 3.18.0 to mitigate this risk.
Original NVD Description
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This issue affects Apache APISIX: from 3.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)