TARI0510 opened a new issue #6335:
URL: https://github.com/apache/apisix/issues/6335


   ### Issue description
   
   2.11.0 version `batch-requests` is enabled by default
   https://github.com/apache/apisix/blob/2.11.0/conf/config-default.yaml#L310
   
   and 2.11.0 doesn't have patch code in 
   
https://github.com/apache/apisix/blob/2.11.0/apisix/plugins/batch-requests.lua#L168
   
   here is CVE-2022-24112's patch code
   
https://github.com/apache/apisix/pull/6251/files#diff-b80ee9fead226c0432f9e78cf5cae941641f9f685c49002f6a51310dd7134892R169
   
   but in announcement, it only refer to 2.10.x version and 2.12.x version
   
   ### Environment
   
   default environment


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


Reply via email to