当前位置:网站首页>API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
API IX JWT auth plug-in has an error. Risk announcement of information disclosure in response (cve-2022-29266)
2022-04-23 15:40:00 【ApacheAPISIX】
Problem description
jwt-auth The plug-in has the security problem of divulging the user's secret key , Because from the dependent Library lua-resty-jwt The returned error message contains sensitive information .
Affects version
Apache APISIX 2.13.0 And all previous versions
Solution
-
Please upgrade to... Now Apache APISIX 2.13.1 And above .
-
If it is not convenient to update the version , Please be there. Apache APISIX Install the corresponding version of the patch package on , Implement refactoring , To bypass the vulnerability ( After the patch package is installed and takes effect , The error message received by the caller will be the repaired error message , No more sensitive information ).
The following patches apply to LTS 2.13.x Or major version :
- https://github.com/apache/apisix/pull/6846
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6858
The following patches apply to the latest LTS 2.10.x edition :
- https://github.com/apache/apisix/pull/6847
- https://github.com/apache/apisix/pull/6855
Vulnerability Details
Vulnerability priority : emergency
Vulnerability disclosure time :2022 year 4 month 20 Japan
CVE Details :https://nvd.nist.gov/vuln/detail/CVE-2022-29266
Contributor profile
The vulnerability is caused by Kingdee software ( China ) Tang Zhongyuan of Co., Ltd 、 Xie Hongfeng and Chen Bing found and reported , Thank you for Apache APISIX Community contribution .

版权声明
本文为[ApacheAPISIX]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231533587450.html
边栏推荐
猜你喜欢
随机推荐
Mysql database explanation (8)
移动金融(自用)
Deeply learn the skills of parameter adjustment
GFS distributed file system (Theory)
Independent operation smart farm Innovation Forum
Node. JS ODBC connection PostgreSQL
Control structure (I)
Squid agent
el-tree实现只显示某一级复选框且单选
推荐搜索 常用评价指标
Modèle de Cluster MySQL et scénario d'application
自主作业智慧农场创新论坛
PHP classes and objects
Cookie&Session
【递归之数的拆分】n分k,限定范围的拆分
Configuration of multi spanning tree MSTP
CVPR 2022 优质论文分享
字符串最后一个单词的长度
pgpool-II 4.3 中文手册 - 入门教程
Code live collection ▏ software test report template Fan Wen is here









