← Back to CVE List
Vulnerability Intelligence Report
apisix/batch-requests plugin allows overwriting the X-REAL-IP header

CVE-2022-24112

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:96.18%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-290 ↗CWE-290 Authentication Bypass by Spoofing

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache APISIX Apache APISIX 2.12 < 2.12.1 (affected), Apache APISIX 2.10 < 2.10.4 (affected), 1.3 < Apache APISIX 1* (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
96.182%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2022-01-28T00:00:00
Published2022-02-11T12:20:13
Last Updated2025-10-21T23:15:46

LINK COPIED TO CLIPBOARD