CVE-2025-46647
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/07/2025
Last modified:
03/07/2025
Description
A vulnerability of plugin openid-connect in Apache APISIX.<br />
<br />
This vulnerability will only have an impact if all of the following conditions are met:<br />
1. Use the openid-connect plugin with introspection mode<br />
2. The auth service connected to openid-connect provides services to multiple issuers<br />
3. Multiple issuers share the same private key and relies only on the issuer being different<br />
<br />
If affected by this vulnerability, it would allow an attacker with a valid account on one of the issuers to log into the other issuer.<br />
<br />
<br />
<br />
<br />
This issue affects Apache APISIX: until 3.12.0.<br />
<br />
Users are recommended to upgrade to version 3.12.0 or higher.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM