Description
It's possible to access the APISIX's Admin API by using the default access token. Therefore, an attacker can interact with the server as an administrator which leads to takeover of the server.
Remediation
Change the default access token and restrict access to API
References
CVE-2020-13945: Apache APISIX's Admin API default access token vulnerability
CVE-2022-24112: Apache APISIX: apisix/batch-requests plugin allows overwriting the X-REAL-IP header