CVE-2025-46647

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/07/2025
Last modified:
03/07/2025

Description

A vulnerability of plugin openid-connect in Apache APISIX.<br /> <br /> This vulnerability will only have an impact if all of the following conditions are met:<br /> 1. Use the openid-connect plugin with introspection mode<br /> 2. The auth service connected to openid-connect provides services to multiple issuers<br /> 3. Multiple issuers share the same private key and relies only on the issuer being different<br /> <br /> If affected by this vulnerability, it would allow an attacker with a valid account on one of the issuers to log into the other issuer.<br /> <br /> <br /> <br /> <br /> This issue affects Apache APISIX: until 3.12.0.<br /> <br /> Users are recommended to upgrade to version 3.12.0 or higher.

References to Advisories, Solutions, and Tools