Rewterz
Rewterz Threat Alert – LokiBot Malware – Active IOCs
November 22, 2021
Rewterz
Rewterz Threat Update – CVE-2021-42321 – Targeted Attacks Exploiting Microsoft Exchange Servers
November 23, 2021

Rewterz Threat Advisory – CVE-2021-43557 – Apache APISIX Directory Vulnerability

Severity

Medium

Analysis Summary

CVE-2021-43557 

Apache APISIX could allow a remote attacker to traverse directories on the system, caused by improper validation of user requests. An attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) in the request_uri parameter to view arbitrary files on the system.

Impact

  • Remote Code Execution

Affected Vendors

Apache

Affected Products

  • Apache APISIX 2.10

Remediation

Upgrade to the latest version of Apache APISIX, available from the Apache Web site.

https://apisix.apache.org/