Impact
A state leakage flaw in Apache APISIX allows a request's authorization scope to persist into subsequent requests on the same API route, effectively expanding the permissions available to an attacker. The bug stems from a static permission list mutation that is not reset between requests, violating consistent access‑control enforcement and granting unauthorized access to protected resources. This weakness is catalogued as CWE-488, indicating that privileges are incorrectly retained across transaction boundaries.
Affected Systems
Apache APISIX versions from 2.3.0 up to, but not including, 3.7.0 are affected. The flaw manifests only when the authz‑keycloak plugin is enabled in supported configurations, exposing the gateway to unintended authorization expansion on any route accessed by a client.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity; the EPSS score is not available, implying no documented exploitation but potential for abuse. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker that can send HTTP requests to the APISIX gateway to trigger the permission persistence, enabling privilege escalation without additional privileges. The flaw requires server‑side changes and is mitigated by updating the software.
OpenCVE Enrichment