
CVE-2022-24112:Apache APISIX apisix/batch-requests RCE
CVE-2022-24112: Apache APISIX apisix/batch-requests RCE
nuclei template: CVE-2022-24112.yaml
The essence of this vulnerability is similar to CVE-2021-45232, both bypass authorization or are unauthenticated, to execute malicious filter_func or script in a route to execute commands.
X-Real-IP can be 127.0.0.1, localhost or 2130706433pipeline is required, the following is a description of its body field valuesmethod is fixed to PUTuri must exist, this is also the URL that needs to be accessed after exp to triggerplugins, upstream/upstream_id, service_id must exist. For details, refer to the official documentationIf service_id is not available, it can be replaced with \"upstream\":{\"type\":\"roundrobin\",\"nodes\":{\"httpbin.org:80\":1}}
References: