CVE-2025-30143
CVE-2025-30143
Título es
CVE-2025-30143
Lun, 17/03/2025 – 16:15
Tipo
CWE-79
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-30143
Descripción en
Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.
17/03/2025
17/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
5.40
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://github.com/geo-chen/Akamai/blob/main/README.md#cve-2025-30143—waf-bypass-in-akamai-ase-application-security-edge-due-to-obfuscated-payload-leading-to-reflected-xss
https://techdocs.akamai.com/app-api-protector/changelog/dec-9-2024-waf-rule-updates
Enviar en el boletín
Off
