Intel

AIKIDO-2025-10465

github.com/athenZ/Athenz is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere

Exposure of Sensitive System Information to an Unauthorized Control Sphere Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 15, 2025

7

Low Risk

This Affects:

GOgithub.com/athenZ/Athenz
1.12.13 - 1.12.19
Fixed in 1.12.20
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to sensitive information exposure due to improper logging of CSRF tokens and Okta callback URIs, which could allow an attacker to intercept these values from log files or system outputs and use them to potentially predict CSRF token algorithm logic, or manipulate authentication flows by replaying captured tokens or redirecting to malicious callback URIs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/athenZ/Athenz is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 1.12.13 - 1.12.19.

How to fix this

Upgrade the github.com/athenZ/Athenz library to the patch version.