Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2455-m68h-qwxv

Опубликовано: 19 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 8.1

Описание

Incorrect Authorization vulnerability in Apache APISIX.

An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Incorrect Authorization vulnerability in Apache APISIX.

An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

EPSS

Процентиль: 21%
0.00285
Низкий

5.3 Medium

CVSS4

8.1 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 8.1
fstec
около 1 месяца назад

Уязвимость плагина authz-casdoor облачного API-шлюза Apache APISIX, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 21%
0.00285
Низкий

5.3 Medium

CVSS4

8.1 High

CVSS3

Дефекты

CWE-863