Vulnerability in OpenID Connect Plugin for Apache APISIX
CVE-2025-46647

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 July 2025

What is CVE-2025-46647?

A vulnerability exists in the OpenID Connect plugin for Apache APISIX where, under specific conditions, an attacker with valid credentials from one issuer can gain unauthorized access to services associated with another issuer. This occurs when the plugin is used in introspection mode, multiple issuers share the same private key, and the auth service is configured to serve multiple issuers without proper separation. It is crucial for users of Apache APISIX to upgrade to version 3.12.0 or higher to mitigate this security risk.

Affected Version(s)

Apache APISIX 0 < 3.12.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tiernan Messmer
.