Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2025/VULN420
_____________________________________________________________________

DATE                : 08/07/2025

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache APISIX Java Plugin Runner
                          versions prior to 0.6.0.

=====================================================================
https://lists.apache.org/thread/qwxnxolt0j5nvjfpr0mlz6h7nrtvyzng
_____________________________________________________________________

CVE-2025-27446: Apache APISIX Java Plugin Runner: Local listening
file permissions in APISIX plugin runner allow a local attacker to
elevate privileges


Severity: low

Affected versions:

- Apache APISIX Java Plugin Runner
(org.apache.apisix:apisix-plugin-runner) 0.2.0 through 0.5.0

Description:

Incorrect Permission Assignment for Critical Resource vulnerability in
Apache APISIX(java-plugin-runner).

Local listening file permissions in APISIX plugin runner allow a local
attacker to elevate privileges.
This issue affects Apache APISIX(java-plugin-runner): from 0.2.0 through 0.5.0.

Users are recommended to upgrade to version 0.6.0 or higher, which
fixes the issue.

Credit:

Benoit TELLIER (reporter)

References:
https://apisix.apache.orghttps://www.cve.org/CVERecord?id=CVE-2025-27446


-- 

*MembPhis*
My GitHub: https://github.com/membphis
Apache APISIX: https://github.com/apache/apisix

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
