当前位置:网站首页>API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
2022-04-23 01:02:00 【InfoQ】
Problem description
lua-resty-jwtAffects version
Solution
- Please upgrade to... Now Apache APISIX 2.13.1 And above .
- If it is not convenient to update the version , Please be there. Apache APISIX Install the corresponding version of the patch package on , Implement refactoring , To bypass the vulnerability ( After the patch package is installed and takes effect , The error message received by the caller will be the repaired error message , No more sensitive information ).
- https://github.com/apache/apisix/pull/6846
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6858
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6855
Vulnerability Details
Contributor profile

版权声明
本文为[InfoQ]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204221058513555.html
边栏推荐
- leetcode 134. 加油站
- This new feature of C 11, I would like to call it the strongest!
- Multi surveyor Xiao sir, Gongshu campus, Hangzhou_ Senior gold medal lecturer_ Resume practice
- What happens when you run the NPM install command?
- [server data recovery] data recovery case of server crash after the hard disk of the server is flooded
- In depth report: in the heterogeneous era, chips need to integrate multiple templates
- Essay 8: error in readpng (paste (location, "/", pattern. Type [i], ". PNG", Sep = "): unable to open C:/
- Deloitte 2022 technology trend: it self subversion, technology cross-border integration and innovation
- L2-020 Kung Fu successor (25 points)
- Flash project cross domain interception and DBM database learning [Baotou cultural and creative website development]
猜你喜欢

Design and application of intelligent lighting control system in hospital

Smart business card applet business card details page function implementation key code

Workplace PUA, five sins of managers

Selection and evolution of microservices under cloud native architecture

IMX6ULL裸机开发之硬件SPI分析及配置过程

Information system project management - project initiation management

Lightly: a new generation of go IDE

员工公寓楼建设项目电力监控系统的研究与应用

io_ Application of ring technology in distributed cloud native database

The thymeleaf template < img th: SRC = "${map. User. Headerurl}" used in idea reports an error cannot resolve 'user‘
随机推荐
Lightly: a new generation of cloud IDE
Originally, this is the correct posture for developers to open world book day!
[ACTF2020 新生赛]Include
智能照明控制系统在医院的设计与应用
Android international area code, registered mobile phone number code and list of common cities, Android memory optimization interview
2.58 - write the program is little endian, which returns 1 when compiled and run on the small end method machine and 0 when compiled and run on the large end method machine. This program should be abl
L2-023 graph coloring problem (25 points)
Leetcode 134. Station - service
[HCTF 2018]admin
Multi surveyor Xiao sir_ Senior gold medal lecturer_ Interview questions
ethtool查看网卡统计信息的流程
Real time monitoring and management of distribution circuit power consumption of acrel-2000 power monitoring system in xingqingfang Xinxing square distribution substation
Deep learning basic learning - RNN and ltsm
Alibaba cloud container & Service Grid product technology trends (202203)
The more "intelligent" the machine is, the easier it is for data taggers to be eliminated? Manfu Technology
The common public page cannot be imported into the templates subset directory of thymeleaf, otherwise an error will be reported: template parsing error, error reason: the reference path of the public
IMX6ULL裸机开发之配置eLCDIF点亮RGB液晶屏分析及配置过程
Software testing immortal documents, even Ali interviewers said it was too detailed. Understanding these directly is P7 level
be based on. NETCORE development blog project starblog - (2) environment preparation and creation project
This new feature of C 11, I would like to call it the strongest!