PT-2025-44457 · Apache · Apache Apisix

Published

2025-10-30

·

Updated

2025-11-06

·

CVE-2025-62232

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache APISIX versions prior to 3.14
Description A flaw exists where sensitive data, specifically usernames and passwords used in basic authentication, are exposed through logging. When the log level is set to INFO or DEBUG, these credentials are written in plaintext to error logs and subsequently forwarded to log sinks, potentially leading to credential compromise if log access is unauthorized.
Recommendations Upgrade to version 3.14 or later to address this issue.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BIT-APISIX-2025-62232
CVE-2025-62232

Affected Products

Apache Apisix