[ANNOUNCE] Apache APISIX 3.2.0 has been released

2023-03-10 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 3.2.0 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is

[ANNOUNCE] Apache APISIX 2.15.3 has been released

2023-03-10 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.15.3 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX

[ANNOUNCE] Apache APISIX 2.15.2 has been released

2023-02-08 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.15.2 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX

[ANNOUNCE] Apache APISIX 3.1.0 has been released

2022-12-30 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 3.1.0 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is

[ANNOUNCE] Apache APISIX 2.15.1 has been released

2022-11-18 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.15.1 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX

[ANNOUNCE] Apache APISIX 3.0.0-beta has been released

2022-09-29 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 3.0.0-beta has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache

[ANNOUNCE] Apache APISIX 2.13.3 has been released

2022-08-26 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.13.3 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX

[ANNOUNCE] Apache APISIX 2.14.1 has been released

2022-05-30 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.14.1 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX

CVE-2022-25757: Apache APISIX: the body_schema check in request-validation plugin can be bypassed

2022-03-28 Thread Zexuan Luo
Severity: low Description: When decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. For example,

[ANNOUNCE] Apache APISIX 2.12.1 has been released

2022-02-11 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.12.1 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX

CVE-2022-24112: Apache APISIX: apisix/batch-requests plugin allows overwriting the X-REAL-IP header

2022-02-11 Thread Zexuan Luo
Severity: high Description: An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API

CVE-2021-43557: Apache APISIX: Path traversal in request_uri variable

2021-11-22 Thread Zexuan Luo
Severity: moderate Description: The uri-block plugin in APISIX uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list

[ANNOUNCE] Apache APISIX 2.10.0 has been release

2021-09-30 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.10.0 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX

[ANNOUNCE] Apache APISIX Go Plugin Runner 0.2.0 has been released

2021-09-05 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX Go Plugin Runner 0.2.0 has been released. Apache APISIX Go Plugin Runner runs Apache APISIX plugins written in Go. It is Implemented as a sidecar that accompanies APISIX. Apache APISIX is a cloud-native microservices

[ANNOUNCE] Apache APISIX 2.9 has been release

2021-08-31 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.9 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is

[ANNOUNCE] Apache APISIX Go Plugin Runner 0.1.0 has been released

2021-07-22 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX Go Plugin Runner 0.1.0 has been released. Apache APISIX Go Plugin Runner runs Apache APISIX plugins written in Go. It is Implemented as a sidecar that accompanies APISIX. Apache APISIX is a cloud-native microservices

[ANNOUNCE] Apache APISIX Java Plugin Runner 0.1 has been released

2021-07-16 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX Java Plugin Runner 0.1 has been released. Apache APISIX Java Plugin Runner runs Apache APISIX plugins written in Java. It is Implemented as a sidecar that accompanies APISIX. Apache APISIX is a cloud-native

[ANNOUNCE] Apache APISIX 2.6 has been release

2021-05-25 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.6 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is

[ANNOUNCE] Apache APISIX 2.5 has been release

2021-04-06 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.5 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is

[ANNOUNCE] Apache APISIX 2.4 has been release

2021-03-05 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.4 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is

[ANNOUNCE] Apache APISIX 2.3 has been released

2021-02-10 Thread Zexuan Luo
Hi folks, The Apache APISIX community is glad to announce that Apache APISIX 2.3 has been released. Apache APISIX is a cloud-native microservices API gateway, delivering the ultimate performance, security, open-source and scalable platform for all your APIs and microservices. Apache APISIX is