当前位置:网站首页>API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
2022-04-23 15:40:00 【ApacheAPISIX】
Problem description
jwt-auth
The plug-in has the security problem of divulging the user's secret key , Because from the dependent Library lua-resty-jwt
The returned error message contains sensitive information .
Affects version
Apache APISIX 2.13.0 And all previous versions
Solution
-
Please upgrade to... Now Apache APISIX 2.13.1 And above .
-
If it is not convenient to update the version , Please be there. Apache APISIX Install the corresponding version of the patch package on , Implement refactoring , To bypass the vulnerability ( After the patch package is installed and takes effect , The error message received by the caller will be the repaired error message , No more sensitive information ).
The following patches apply to LTS 2.13.x Or major version :
- https://github.com/apache/apisix/pull/6846
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6858
The following patches apply to the latest LTS 2.10.x edition :
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6855
Vulnerability Details
Vulnerability priority : emergency
Vulnerability disclosure time :2022 year 4 month 20 Japan
CVE Details :https://nvd.nist.gov/vuln/detail/CVE-2022-29266
Contributor profile
The vulnerability is caused by Kingdee software ( China ) Tang Zhongyuan of Co., Ltd 、 Xie Hongfeng and Chen Bing found and reported , Thank you for Apache APISIX Community contribution .
版权声明
本文为[ApacheAPISIX]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231533587450.html
边栏推荐
- What role does the software performance test report play? How much is the third-party test report charged?
- G007-hwy-cc-estor-03 Huawei Dorado V6 storage simulator construction
- How did the computer reinstall the system? The display has no signal
- 服务器中毒了怎么办?服务器怎么防止病毒入侵?
- 自动化测试框架常见类型▏自动化测试就交给软件测评机构
- Educational codeforces round 127 A-E problem solution
- Treatment of idempotency
- WPS品牌再升级专注国内,另两款国产软件低调出国门,却遭禁令
- s16.基于镜像仓库一键安装containerd脚本
- Use of common pod controller of kubernetes
猜你喜欢
G007-hwy-cc-estor-03 Huawei Dorado V6 storage simulator construction
For examination
网站压测工具Apache-ab,webbench,Apache-Jemeter
Deep learning - Super parameter setting
Recommended search common evaluation indicators
字节面试 transformer相关问题 整理复盘
为啥禁用外键约束
使用 Bitnami PostgreSQL Docker 镜像快速设置流复制集群
IronPDF for . NET 2022.4.5455
Knn,Kmeans和GMM
随机推荐
Mysql database explanation (VII)
How did the computer reinstall the system? The display has no signal
为啥禁用外键约束
Timing model: gated cyclic unit network (Gru)
Go并发和通道
移动app软件测试工具有哪些?第三方软件测评小编分享
Load Balancer
Deeply learn the skills of parameter adjustment
Mysql database explanation (IX)
Explanation of redis database (I)
MySQL集群模式與應用場景
时序模型:长短期记忆网络(LSTM)
MySQL query library size
[backtrader source code analysis 18] Yahoo Py code comments and analysis (boring, interested in the code, you can refer to)
JSON date time date format
什么是CNAS认证?CNAS认可的软件测评中心有哪些?
Explanation 2 of redis database (redis high availability, persistence and performance management)
Crawling fragment of a button style on a website
Code live collection ▏ software test report template Fan Wen is here
Common types of automated testing framework ▏ automated testing is handed over to software evaluation institutions