In Apache APISIX Dashboard versions prior to 2.10.1, the Manager API uses both the 'droplet' and 'gin' frameworks. While authentication middleware is implemented for APIs developed with 'droplet', some APIs directly use the 'gin' framework interfaces, thereby bypassing authentication controls. This allows unauthenticated access to certain API endpoints.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script targeting Apache APISIX Dashboard. The exploit abuses the /apisix/admin/migrate/import API endpoint to import a malicious route configuration. This configuration injects a Lua script that executes OS commands received via the 'cmd' HTTP header of requests to a newly created random URI. The script disables SSL verification warnings, generates a random route, and attempts to import the payload. If successful, it prints the URI for remote command execution. The repository consists of a README and a single exploit script (apisix_dashboard_rce.py). The exploit is operational and provides remote command execution capabilities on vulnerable APISIX Dashboard instances.
This repository is a Go-based exploit tool targeting two vulnerabilities in Apache APISIX: CVE-2021-45232 (unauthenticated admin API access) and CVE-2020-13945 (default API key usage). The tool supports both single and batch target modes, reading targets from a file or command-line argument. The main logic is in the DataHandle package, with functions to check for unauthenticated access and default key vulnerabilities. For CVE-2021-45232, the tool attempts to export and import configuration via the admin API, injecting a Lua script that allows remote OS command execution. For CVE-2020-13945, it uses the default API key to create a malicious route with a Lua script, then triggers it to achieve code execution. The exploit is operational, providing a working getshell if the target is vulnerable. The endpoints targeted are the APISIX admin API paths, and the payload is a Lua script injected via HTTP requests. The repository is structured with Go source files under DataHandle, a main.go entry point, and a README with usage instructions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.