Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h244-w3g4-3cv4

Опубликовано: 26 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 8.8

Описание

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.

This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly.

This issue affects Apache APISIX: from 3.11.0 through 3.17.0.

Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.

This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly.

This issue affects Apache APISIX: from 3.11.0 through 3.17.0.

Users are recommended to upgrade to version 3.18.0, which fixes the issue.

EPSS

Процентиль: 51%
0.00677
Низкий

5.3 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-807

Связанные уязвимости

CVSS3: 8.8
nvd
27 дней назад

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This issue affects Apache APISIX: from 3.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

EPSS

Процентиль: 51%
0.00677
Низкий

5.3 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-807