Apache APISIX
cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*
- >= 2.99.0, <= 3.15.0
A vulnerability allowing cleartext transmission of sensitive information has been identified in the Apache APISIX plugin for Tencent Cloud CLS log export. This issue affects versions 2.99.0 prior to 3.15.0, where log export is conducted over unencrypted HTTP. Users are advised to upgrade to version 3.16.0, which addresses this vulnerability.
Exploitation of this vulnerability could lead to the interception of sensitive information transmitted in plaintext over HTTP during the log export process.
Users should upgrade to Apache APISIX version 3.16.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.