CVE-2022-29266
20.04.2022, 08:15
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
apache | apisix | 𝑥 < 2.13.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration