Apache APISIX Vulnerability Enables Cross-Issuer Access Under Misconfigurations

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Apache APISIX Vulnerability Enables Cross-Issuer Access Under Misconfigurations

Post by Shane1145 »

A newly disclosed vulnerability, CVE-2025-46647, has been identified in the openid-connect plugin of Apache APISIX, a widely used open-source API gateway.

This flaw, rated as important, could allow attackers to gain unauthorized access across different identity issuers under specific misconfigurations.


https://gbhackers.com/apache-apisix-vulnerability/
Post Reply