Hello

Vào CN, 6 thg 7, 2025 lúc 12:38 YuanSheng Wang <membp...@apache.org> đã
viết:

> Severity: low
>
> Affected versions:
>
> - Apache APISIX Java Plugin Runner
> (org.apache.apisix:apisix-plugin-runner) 0.2.0 through 0.5.0
>
> Description:
>
> Incorrect Permission Assignment for Critical Resource vulnerability in
> Apache APISIX(java-plugin-runner).
>
> Local listening file permissions in APISIX plugin runner allow a local
> attacker to elevate privileges.
> This issue affects Apache APISIX(java-plugin-runner): from 0.2.0 through
> 0.5.0.
>
> Users are recommended to upgrade to version 0.6.0 or higher, which
> fixes the issue.
>
> Credit:
>
> Benoit TELLIER (reporter)
>
> References:
> https://apisix.apache.orghttps://www.cve.org/CVERecord?id=CVE-2025-27446
>
>
>
> --
>
> *MembPhis*
> My GitHub: https://github.com/membphis
> Apache APISIX: https://github.com/apache/apisix
>

Reply via email to