PT-2026-50898 · Apache · Apache Apisix
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache APISIX versions 3.0.0 through 3.16.0
Description
A Cross-Site Request Forgery (CSRF) issue exists in the
cas-auth plugin under default configurations. This allows a remote attacker to trick a victim into visiting a malicious webpage, causing the victim's browser to be authenticated as a different identity. Consequently, actions performed by the victim are attributed to the attacker's identity.Recommendations
Upgrade to version 3.17.0.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Apisix