Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-368x-wmmg-hq5c

Опубликовано: 22 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apollo has potential access control security issue in eureka

Impact

If users expose the apollo-configservice to the internet (which is not recommended), there are potential security issues since there is no authentication feature enabled for the built-in eureka service. Malicious hackers may access eureka directly to mock apollo-configservice and apollo-adminservice .

Patches

Login authentication for eureka was added in https://github.com/apolloconfig/apollo/pull/4663 and was released in v2.1.0.

Workarounds

To fix the potential issue without upgrading, simply follow the advice that does not expose apollo-configservice to the internet.

References

Apollo Security Guidence

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

com.ctrip.framework.apollo:apollo

maven
Затронутые версииВерсия исправления

< 2.1.0

2.1.0

EPSS

Процентиль: 29%
0.00107
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service. Malicious hackers may access eureka directly to mock apollo-configservice and apollo-adminservice. Login authentication for eureka was added in version 2.1.0. As a workaround, avoid exposing apollo-configservice to the internet.

EPSS

Процентиль: 29%
0.00107
Низкий

7.5 High

CVSS3

Дефекты

CWE-306