Apache APISIX
cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*
- 1.0
A vulnerability in Apache APISIX basic authentication logging has been identified, where plaintext usernames and passwords are written to error logs. This occurs when the log level is set to INFO or DEBUG, creating a significant risk of credential compromise through log access. The issue affects Apache APISIX version 1.0.
Exploitation of this vulnerability leads to unauthorized exposure of plaintext credentials, including usernames and passwords, which could be accessed through the application's log files.
Users are advised to upgrade to Apache APISIX version 3.14, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.