Rewterz Threat Alert – LokiBot Malware – Active IOCs
November 22, 2021Rewterz Threat Update – CVE-2021-42321 – Targeted Attacks Exploiting Microsoft Exchange Servers
November 23, 2021Rewterz Threat Alert – LokiBot Malware – Active IOCs
November 22, 2021Rewterz Threat Update – CVE-2021-42321 – Targeted Attacks Exploiting Microsoft Exchange Servers
November 23, 2021Severity
Medium
Analysis Summary
CVE-2021-43557
Apache APISIX could allow a remote attacker to traverse directories on the system, caused by improper validation of user requests. An attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) in the request_uri parameter to view arbitrary files on the system.
Impact
- Remote Code Execution
Affected Vendors
Apache
Affected Products
- Apache APISIX 2.10
Remediation
Upgrade to the latest version of Apache APISIX, available from the Apache Web site.