Critical severity9.8CISA KEVNVD Advisory· Published Feb 11, 2022· Updated Jun 17, 2026
CVE-2022-24112
CVE-2022-24112
Description
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/166228/Apache-APISIX-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/166328/Apache-APISIX-2.12.1-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.openwall.com/lists/oss-security/2022/02/11/3nvdMailing ListMitigationThird Party Advisory
- lists.apache.org/thread/lcdqywz8zy94mdysk7p3gfdgn51jmt94nvdMailing ListMitigationVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.