CVE-2025-62232: Apache APISIX: basic-auth logs plaintext credentials at info level
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit: https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.14
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62232?
CVE-2025-62232 has been categorized as a high severity vulnerability due to the potential for credential compromise.
How do I fix CVE-2025-62232?
To mitigate CVE-2025-62232, upgrade to Apache APISIX version 3.14 or later, where the vulnerability has been addressed.
What systems are affected by CVE-2025-62232?
CVE-2025-62232 specifically affects Apache APISIX versions prior to 3.14.
What kind of data is exposed in CVE-2025-62232?
CVE-2025-62232 exposes plaintext usernames and passwords through error logs due to basic-auth logging.
What are the implications of not addressing CVE-2025-62232?
Failing to address CVE-2025-62232 increases the risk of credential theft through unauthorized access to logs.