当前位置:网站首页>API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
2022-04-23 15:40:00 【ApacheAPISIX】
Problem description
jwt-auth The plug-in has the security problem of divulging the user's secret key , Because from the dependent Library lua-resty-jwt The returned error message contains sensitive information .
Affects version
Apache APISIX 2.13.0 And all previous versions
Solution
-
Please upgrade to... Now Apache APISIX 2.13.1 And above .
-
If it is not convenient to update the version , Please be there. Apache APISIX Install the corresponding version of the patch package on , Implement refactoring , To bypass the vulnerability ( After the patch package is installed and takes effect , The error message received by the caller will be the repaired error message , No more sensitive information ).
The following patches apply to LTS 2.13.x Or major version :
- https://github.com/apache/apisix/pull/6846
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6858
The following patches apply to the latest LTS 2.10.x edition :
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6855
Vulnerability Details
Vulnerability priority : emergency
Vulnerability disclosure time :2022 year 4 month 20 Japan
CVE Details :https://nvd.nist.gov/vuln/detail/CVE-2022-29266
Contributor profile
The vulnerability is caused by Kingdee software ( China ) Tang Zhongyuan of Co., Ltd 、 Xie Hongfeng and Chen Bing found and reported , Thank you for Apache APISIX Community contribution .

版权声明
本文为[ApacheAPISIX]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231533587450.html
边栏推荐
- Independent operation smart farm Innovation Forum
- 现在做自媒体能赚钱吗?看完这篇文章你就明白了
- Use of common pod controller of kubernetes
- Today's sleep quality record 76 points
- Leetcode学习计划之动态规划入门day3(198,213,740)
- 通过 PDO ODBC 将 PHP 连接到 MySQL
- Pytorch中named_parameters、named_children、named_modules函数
- 基础贪心总结
- The El tree implementation only displays a certain level of check boxes and selects radio
- 携号转网最大赢家是中国电信,为何人们嫌弃中国移动和中国联通?
猜你喜欢

Recommended search common evaluation indicators

What if the server is poisoned? How does the server prevent virus intrusion?

Basic concepts of website construction and management

CVPR 2022 优质论文分享

Codejock Suite Pro v20.3.0

Codejock Suite Pro v20. three

Redis主从复制过程

群体智能自主作业智慧农场项目启动及实施方案论证会议

Redis master-slave replication process

【AI周报】英伟达用AI设计芯片;不完美的Transformer要克服自注意力的理论缺陷
随机推荐
How to test mobile app?
What if the server is poisoned? How does the server prevent virus intrusion?
pgpool-II 4.3 中文手册 - 入门教程
MySQL Cluster Mode and application scenario
Code live collection ▏ software test report template Fan Wen is here
What is CNAs certification? What are the software evaluation centers recognized by CNAs?
Mysql database explanation (IX)
大厂技术实现 | 行业解决方案系列教程
山寨版归并【上】
Node.js ODBC连接PostgreSQL
Upgrade MySQL 5.1 to 5.68
Cookie&Session
fatal error: torch/extension. h: No such file or directory
[backtrader source code analysis 18] Yahoo Py code comments and analysis (boring, interested in the code, you can refer to)
Application of Bloom filter in 100 million flow e-commerce system
通过 PDO ODBC 将 PHP 连接到 MSSQL
Mumu, go all the way
ICE -- 源码分析
多级缓存使用
Today's sleep quality record 76 points