Server-Side Request Forgery Vulnerability in OpenZiti Admin Panel
CVE-2025-27501

8.6HIGH

Key Information:

Vendor

Openziti

Vendor
CVE Published:
3 March 2025

What is CVE-2025-27501?

The OpenZiti admin panel exposes an unauthenticated endpoint that allows attackers to exploit a flaw through user-supplied URL parameters. This can lead to a Server-Side Request Forgery (SSRF), where unauthorized requests are made to an OpenZiti Controller, potentially compromising system security. The vulnerability has been addressed in version 3.7.1, which transitioned the request handling from the server side to the client side, effectively mitigating the risk by ensuring that the node’s identity cannot be misused for gaining unintended permissions.

Affected Version(s)

ziti-console < 3.7.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.