CVE-2020-13945 describes an insufficient access control vulnerability in Apache APISIX versions 1.2 through 1.5. If an administrator enables the Admin API and removes IP restriction rules, the default token can be used to access sensitive management data, potentially leading to unauthorized information disclosure. This vulnerability carries a CVSS score of 6.5 (Medium) due to its network-based attack vector and high confidentiality impact, and it has an exceptionally high EPSS score, indicating a strong likelihood of exploitation. While not on the CISA KEV catalog, public exploit modules exist, including a Metasploit module for Remote Code Execution and Nuclei templates, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.2, <= 1.5CPE matchmatch criteria | cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.