PT-2025-9538 · Openziti · Openziti

Diabl0-Sec

·

Published

2025-03-03

·

Updated

2025-03-05

·

CVE-2025-27501

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenZiti versions prior to 3.7.1
Description The issue concerns an endpoint on the admin panel that can be accessed without authentication. This endpoint accepts a user-supplied URL parameter to connect to an OpenZiti Controller, which can lead to a Server-Side Request Forgery (SSRF) vulnerability. The SSRF vulnerability allows an attacker to perform server-side requests, potentially exploiting the identity of the node to gain additional permissions.
Recommendations For versions prior to 3.7.1, update to version 3.7.1 to fix the vulnerability, as it moves the request to the external controller from the server side to the client side, eliminating the potential for SSRF exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27501
GHSA-FQXH-VFV5-8QJP

Affected Products

Openziti