漏洞描述 Apache APISIX 是一个高性能全动态的云原生API 网关,该网关存在未授权访问接口,攻击者无需登录 Apache APISIX Dashboard即可访问某些接口,从而进行未授权更改或获取 Apache APISIX Route、Upstream、Service 等相关配置信息,并造成SSRF、攻击者搭建恶意流量代理和任意代码执行等问题。
相关漏洞推荐 Apache Airflow Providers Edge3 设计缺陷漏洞 POC unauth-munin: Munin Monitoring Dashboard - Exposure Apache Struts2 资源释放不当漏洞 POC CVE-2018-17082: Apache2 - Transfer-Encoding Chunked XSS POC apache-hive-config: Apache Hive Configuration - Exposure POC unauth-akhq-dashboard: AKHQ Dashboard - Unauthenticated Access POC unauth-hawkeye-dashboard: Unauth Hawkeye Dashboard - Detect POC unauth-phoenix-dashboard: Unauth Phoenix Dashboard - Detect POC unauth-supervisor-dashboard: Unauth Supervisor Dashboard - Detect (CVE-2025-11461)Frappe CRM 1.53.1 Dashboard Controller SQL注入漏洞 Apache Tomcat URL重写绕过漏洞 (CVE-2025-55752) Apache Tomcat 存在路径遍历漏洞(CVE-2025-55752) Apache ActiveMQ NMS AMQP Client 反序列化漏洞