A vulnerability of plugin openid-connect in Apache APISIX...
Moderate severity
Unreviewed
Published
Jul 2, 2025
to the GitHub Advisory Database
•
Updated Nov 5, 2025
Description
Published by the National Vulnerability Database
Jul 2, 2025
Published to the GitHub Advisory Database
Jul 2, 2025
Last updated
Nov 5, 2025
A vulnerability of plugin openid-connect in Apache APISIX.
This vulnerability will only have an impact if all of the following conditions are met:
If affected by this vulnerability, it would allow an attacker with a valid account on one of the issuers to log into the other issuer.
This issue affects Apache APISIX: until 3.12.0.
Users are recommended to upgrade to version 3.12.0 or higher.
References