Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q562-qrm6-7p84

Опубликовано: 19 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 7.2

Описание

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.

The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token.

This issue affects Apache APISIX: from 3.0.0 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.

The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token.

This issue affects Apache APISIX: from 3.0.0 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

EPSS

Процентиль: 33%
0.00409
Низкий

2.1 Low

CVSS4

7.2 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 месяцев назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 7.2
fstec
около 2 месяцев назад

Уязвимость облачного API-шлюза Apache APISIX, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес

EPSS

Процентиль: 33%
0.00409
Низкий

2.1 Low

CVSS4

7.2 High

CVSS3

Дефекты

CWE-601