A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to multiple issuers 3. Multiple issuers share the same private key and relies only on the issuer being different If affected by this vulnerability, it would allow an attacker with a valid account on one of the issuers to log into the other issuer. This issue affects Apache APISIX: until 3.12.0. Users are recommended to upgrade to version 3.12.0 or higher.
History

Wed, 02 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to multiple issuers 3. Multiple issuers share the same private key and relies only on the issuer being different If affected by this vulnerability, it would allow an attacker with a valid account on one of the issuers to log into the other issuer. This issue affects Apache APISIX: until 3.12.0. Users are recommended to upgrade to version 3.12.0 or higher.
Title Apache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connect
Weaknesses CWE-302
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-07-02T11:08:47.179Z

Updated: 2025-07-02T20:47:21.822Z

Reserved: 2025-04-26T15:02:23.758Z

Link: CVE-2025-46647

cve-icon Vulnrichment

Updated: 2025-07-02T20:46:10.624Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-02T12:15:28.227

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-46647

cve-icon Redhat

No data.