← back
CVE-2020-13945

CVE-2020-13945

40Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 73%
from disclosure to weapon0 days
Published on NVDDec 7
metasploitDec 7
exploitation probability
73%top 1% of all CVEs
observed exploitation
nono source reports it
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.