当前位置:网站首页>API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
2022-04-23 15:40:00 【ApacheAPISIX】
Problem description
jwt-auth The plug-in has the security problem of divulging the user's secret key , Because from the dependent Library lua-resty-jwt The returned error message contains sensitive information .
Affects version
Apache APISIX 2.13.0 And all previous versions
Solution
-
Please upgrade to... Now Apache APISIX 2.13.1 And above .
-
If it is not convenient to update the version , Please be there. Apache APISIX Install the corresponding version of the patch package on , Implement refactoring , To bypass the vulnerability ( After the patch package is installed and takes effect , The error message received by the caller will be the repaired error message , No more sensitive information ).
The following patches apply to LTS 2.13.x Or major version :
- https://github.com/apache/apisix/pull/6846
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6858
The following patches apply to the latest LTS 2.10.x edition :
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6855
Vulnerability Details
Vulnerability priority : emergency
Vulnerability disclosure time :2022 year 4 month 20 Japan
CVE Details :https://nvd.nist.gov/vuln/detail/CVE-2022-29266
Contributor profile
The vulnerability is caused by Kingdee software ( China ) Tang Zhongyuan of Co., Ltd 、 Xie Hongfeng and Chen Bing found and reported , Thank you for Apache APISIX Community contribution .

版权声明
本文为[ApacheAPISIX]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231533587450.html
边栏推荐
- Upgrade MySQL 5.1 to 5.68
- 开源项目推荐:3D点云处理软件ParaView,基于Qt和VTK
- 字节面试 transformer相关问题 整理复盘
- Treatment of idempotency
- Advantages, disadvantages and selection of activation function
- 码住收藏▏软件测试报告模板范文来了
- Explanation of redis database (III) redis data type
- 移动app软件测试工具有哪些?第三方软件测评小编分享
- 控制结构(二)
- Code live collection ▏ software test report template Fan Wen is here
猜你喜欢
随机推荐
cadence SPB17. 4 - Active Class and Subclass
北京某信护网蓝队面试题目
Deeply learn the skills of parameter adjustment
MySQL Cluster Mode and application scenario
考试考试自用
自主作业智慧农场创新论坛
一刷313-剑指 Offer 06. 从尾到头打印链表(e)
Deep learning - Super parameter setting
网站建设与管理的基本概念
Rsync + inotify remote synchronization
How did the computer reinstall the system? The display has no signal
携号转网最大赢家是中国电信,为何人们嫌弃中国移动和中国联通?
c语言---指针进阶
Basic concepts of website construction and management
幂等性的处理
【AI周报】英伟达用AI设计芯片;不完美的Transformer要克服自注意力的理论缺陷
Introduction to dynamic programming of leetcode learning plan day3 (198213740)
Why disable foreign key constraints
Upgrade MySQL 5.1 to 5.67
Explanation of redis database (IV) master-slave replication, sentinel and cluster









