PT-2025-9538 · Openziti · Openziti
Diabl0-Sec
·
Published
2025-03-03
·
Updated
2025-03-05
·
CVE-2025-27501
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenZiti versions prior to 3.7.1
Description
The issue concerns an endpoint on the admin panel that can be accessed without authentication. This endpoint accepts a user-supplied URL parameter to connect to an OpenZiti Controller, which can lead to a Server-Side Request Forgery (SSRF) vulnerability. The SSRF vulnerability allows an attacker to perform server-side requests, potentially exploiting the identity of the node to gain additional permissions.
Recommendations
For versions prior to 3.7.1, update to version 3.7.1 to fix the vulnerability, as it moves the request to the external controller from the server side to the client side, eliminating the potential for SSRF exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openziti