Server-Side Request Forgery Vulnerability in OpenZiti Admin Panel
CVE-2025-27501
What is CVE-2025-27501?
The OpenZiti admin panel exposes an unauthenticated endpoint that allows attackers to exploit a flaw through user-supplied URL parameters. This can lead to a Server-Side Request Forgery (SSRF), where unauthorized requests are made to an OpenZiti Controller, potentially compromising system security. The vulnerability has been addressed in version 3.7.1, which transitioned the request handling from the server side to the client side, effectively mitigating the risk by ensuring that the node’s identity cannot be misused for gaining unintended permissions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ziti-console < 3.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
