CVE-2025-27501

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Mar 3, 2025
Updated: Mar 5, 2025
CWE ID 918

Summary

CVE-2025-27501 is a vulnerability affecting OpenZiti, an open-source project aimed at implementing zero trust security. The issue lies in an admin panel endpoint that can be accessed without authentication, enabling attackers to supply a URL parameter to connect to an OpenZiti Controller. This results in a Server-Side Request Forgery (SSRF) vulnerability, potentially allowing unauthorized access to controller functions. OpenZiti's 3.7.1 release mitigates the risk by moving the request to the client side, preventing the server from disclosing its identity and granting unauthorized permissions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share