Apache APISIX
cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*
- >= 2.12.0, <= 3.15.0
A header injection vulnerability has been identified in Apache APISIX versions 2.12.0 prior to 3.15.0. This issue arises in the forward-auth plugin, where an attacker can inject malicious headers by exploiting certain configurations. Users are advised to upgrade to version 3.16.0, which addresses this vulnerability.
Exploitation of this vulnerability allows for header injection, which could be used to manipulate or spoof HTTP headers in requests.
Users are recommended to upgrade to Apache APISIX version 3.16.0, which fixes this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.