oss-sec mailing list archives
CVE-2025-27446: Apache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges
From: YuanSheng Wang <membphis () apache org>
Date: Sun, 6 Jul 2025 11:36:32 +0800
Severity: low Affected versions: - Apache APISIX Java Plugin Runner (org.apache.apisix:apisix-plugin-runner) 0.2.0 through 0.5.0 Description: Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges. This issue affects Apache APISIX(java-plugin-runner): from 0.2.0 through 0.5.0. Users are recommended to upgrade to version 0.6.0 or higher, which fixes the issue. Credit: Benoit TELLIER (reporter) References: https://apisix.apache.orghttps://www.cve.org/CVERecord?id=CVE-2025-27446 -- *MembPhis* My GitHub: https://github.com/membphis Apache APISIX: https://github.com/apache/apisix
Current thread:
- CVE-2025-27446: Apache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges YuanSheng Wang (Jul 06)
