
Cloud Vulnerability DB
A community-led vulnerabilities database
In Apache APISIX Dashboard version 2.6, a security vulnerability was identified that allowed attackers to bypass network access control restrictions. The issue arose when the default listen host value was changed to 0.0.0.0 to facilitate external network access configuration. The vulnerability was designated as CVE-2021-33190 and was subsequently fixed in APISIX Dashboard version 2.6.1 (OpenWall).
The vulnerability was classified under CWE-307 (Improper Restriction of Excessive Authentication Attempts). The security flaw stemmed from the use of a risky function for IP acquisition in the IP allowed list restriction mechanism, which could be exploited to bypass network limitations. Additionally, the system's default account and password were fixed, compounding the security risk (OpenWall, MITRE CVE).
The vulnerability exposed the Apache APISIX Dashboard to potential unauthorized access by allowing attackers to bypass network access control mechanisms. This was particularly critical given the combination of the exposed listen host (0.0.0.0) and fixed default credentials (OpenWall).
The vulnerability could be exploited by leveraging the risky IP acquisition function in combination with the default credentials. The exposed listen host on 0.0.0.0 made the system potentially accessible from external networks, increasing the attack surface (OpenWall).
Two primary mitigation steps were recommended: 1) Change the account password after installation and avoid using the default password, 2) Upgrade to APISIX Dashboard version 2.6.1 or newer, which contains the fix for this vulnerability (OpenWall).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."