Hi Cuong Duy, Please follow the instructions below to unsubscribe:
Step1: Send an email to dev-unsubscr...@apisix.apache.org, then you will receive a confirmation email from dev-h...@apisix.apache.org. Step 2: Reply to dev-h...@apisix.apache.org to confirm that you want to unsubscribe from this mailing list. Once successfully unsubscribed, you will receive a Goodbye email from dev-h...@apisix.apache.org. You can also visit Apache APISIX's website[1] and find step-by-step unsubscribe instructions there. [1]: https://apisix.apache.org/docs/general/join/#unsubscribe-from-the-mailing-list Regards, Yilin Zeng On 2025/07/06 13:58:27 Cuong Duy wrote: > Hi > > Vào CN, 6 thg 7, 2025 lúc 12:37 YuanSheng Wang <membp...@apache.org> đã > viết: > > > Severity: low > > > > Affected versions: > > > > - Apache APISIX Java Plugin Runner > > (org.apache.apisix:apisix-plugin-runner) 0.2.0 through 0.5.0 > > > > Description: > > > > Incorrect Permission Assignment for Critical Resource vulnerability in > > Apache APISIX(java-plugin-runner). > > > > Local listening file permissions in APISIX plugin runner allow a local > > attacker to elevate privileges. > > This issue affects Apache APISIX(java-plugin-runner): from 0.2.0 through > > 0.5.0. > > > > Users are recommended to upgrade to version 0.6.0 or higher, which > > fixes the issue. > > > > Credit: > > > > Benoit TELLIER (reporter) > > > > References: > > https://apisix.apache.orghttps://www.cve.org/CVERecord?id=CVE-2025-27446 > > > > > > -- > > > > *MembPhis* > > My GitHub: https://github.com/membphis > > Apache APISIX: https://github.com/apache/apisix > > >