In versions prior to Apache APISIX 2.10.2, there was a problem of "bypassing partial restrictions" that caused the risk of path penetration by using the $request_uri variable in Apache APISIX Ingress Controller.
Apache APISIX Path traversal in request_uri variable(CVE-2021-43557)
· 2 min read