Impact
This vulnerability is a session fixation flaw (CWE‑352) in the feishu‑auth and dingtalk‑auth plugins of Apache APISIX. An attacker can force a user’s browser to start a session that the attacker controls by clicking a crafted link. Once the victim’s session is hijacked, the attacker can perform any action the user is authorized to carry out, such as uploading files, submitting forms, or binding accounts, all of which are recorded under the attacker’s account.
Affected Systems
Apache APISIX versions 3.17.0 through 3.18.0 contain the vulnerable plugins. All deployments of those versions that enable feishu‑auth or dingtalk‑auth are affected.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity, yet the real impact is serious because the attacker gains the victim’s privileges. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, implying no known widespread exploitation yet. The attack vector requires only a user to click a malicious link, so prevention relies on patching or disabling the plugins, rather than on user education alone.
OpenCVE Enrichment