Medium
Apache APISIX could allow a remote attacker to traverse directories on the system, caused by improper validation of user requests. An attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) in the request_uri parameter to view arbitrary files on the system.
Apache
Upgrade to the latest version of Apache APISIX, available from the Apache Web site.