Home / exploitsPDF  

Apache APISIX Remote Code Execution

Posted on 07 March 2022

Apache APISIX has a default, built-in API token that can be used to obtain full access of the admin API. Access to this API allows for remote LUA code execution through the script parameter added in the 2.x version. This module also leverages another vulnerability to bypass th e IP restriction plugin.

 

TOP