diff --git a/cves/2021/CVE-2021-45232.yaml b/cves/2021/CVE-2021-45232.yaml index b9ba133938..880b97330b 100644 --- a/cves/2021/CVE-2021-45232.yaml +++ b/cves/2021/CVE-2021-45232.yaml @@ -1,7 +1,7 @@ id: CVE-2021-45232 info: - name: Apache APISIX Dashboard <2.10.1 API Unauthorized Access + name: Apache APISIX Dashboard <2.10.1 - API Unauthorized Access author: Mr-xn severity: critical description: In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin.' While all APIs and authentication middleware are developed based on framework `droplet`, some API directly use the interface of framework `gin` thus bypassing their authentication.