Apache APISIX
cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*
- >= 0.7, <= 3.15.0
A vulnerability allowing cleartext transmission of sensitive information exists in Apache APISIX versions 0.7 through 3.15.0. This issue arises because the 'ssl_verify' option in the OpenID Connect plugin is set to false by default, potentially exposing sensitive data during transmission.
Exploitation of this vulnerability could lead to the interception of sensitive information transmitted in cleartext, such as authentication tokens or user data, which could be exploited in various ways depending on the intercepted information.
Users are advised to upgrade to Apache APISIX version 3.16.0 or later, where this issue has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.