Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2025/VULN756
_____________________________________________________________________

DATE                : 31/10/2025

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache APISIX.

=====================================================================
https://lists.apache.org/thread/kwyfcy0cyv93hr4w6ggfc1wn3lgk5s09
_____________________________________________________________________

CVE-2025-62232: Apache APISIX: APISIX basic-auth logs plaintext
credentials at info level

Severity: moderate 

Affected versions:

- Apache APISIX 1.0

Description:

Sensitive data exposure via logging in basic-auth leads to plaintext
usernames and passwords written to error logs and forwarded to log
sinks when log level is INFO/DEBUG. This creates a high risk of
credential compromise through log access.


It has been fixed in the following commit:
https://github.com/apache/apisix/pull/12629 

Users are recommended to upgrade to version 3.14, which fixes this
issue.


References:

https://apisix.apache.org
https://www.cve.org/CVERecord?id=CVE-2025-62232



=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




