PT-2026-50883 · Apache Apisix+1 · Wolf-Rbac+1
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache APISIX versions 1.2.0 through 3.16.0
Description
A Use of Less Trusted Source issue exists where an attacker can leverage the
wolf-rbac plugin under default configuration. This allows for the potential pollution of logs with spoofed identity information and the exploitation of IP-based access control rules.Recommendations
Upgrade to version 3.17.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Apisix
Wolf-Rbac