CVE-2025-30143 Information
Mar 18, 2025
cve
Description
Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.
Reference
https://github.com/geo-chen/Akamai/blob/main/README.md#cve-2025-30143—waf-bypass-in-akamai-ase-application-security-edge-due-to-obfuscated-payload-leading-to-reflected-xss https://techdocs.akamai.com/app-api-protector/changelog/dec-9-2024-waf-rule-updates
Share on: