Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c6c3-h4f7-3962

Опубликовано: 20 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

apollo-portal has potential unauthorized access issue

Impact

A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions.

Patches

The issue was addressed with an input parameter check in #5192, which was released in version 2.3.0.

Workarounds

To mitigate the issue without upgrading, follow the recommended practices to prevent Apollo from being exposed to the internet.

Credits

The vulnerability was reported and reproduced by Lakeswang.

References

For any questions or comments regarding this advisory:

Пакеты

Наименование

com.ctrip.framework.apollo:apollo

maven
Затронутые версииВерсия исправления

< 2.3.0

2.3.0

EPSS

Процентиль: 27%
0.00098
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0.

EPSS

Процентиль: 27%
0.00098
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-284