Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrqp-g94p-gmh7

Опубликовано: 19 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 9.3

Описание

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.

This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity.

Actions the victim takes upstream are then attributed to attackers identity.

This issue affects Apache APISIX: from 3.0.0 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.

This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity.

Actions the victim takes upstream are then attributed to attackers identity.

This issue affects Apache APISIX: from 3.0.0 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

EPSS

Процентиль: 18%
0.00261
Низкий

2.1 Low

CVSS4

9.3 Critical

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 9.3
nvd
около 2 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity. Actions the victim takes upstream are then attributed to attackers identity. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 9.3
fstec
около 2 месяцев назад

Уязвимость плагина cas-auth облачного API-шлюза Apache APISIX, позволяющая нарушителю осуществить CSRF-атаку

EPSS

Процентиль: 18%
0.00261
Низкий

2.1 Low

CVSS4

9.3 Critical

CVSS3

Дефекты

CWE-352