Описание
apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is designed to work in intranet and it doesn't have access control built-in. Malicious hackers may access apollo-adminservice apis directly to access/edit the application's configurations. To fix the potential issue without upgrading, simply follow the advice that do not expose apollo-adminservice to internet.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.1 (исключая)
cpe:2.3:a:ctrip:apollo:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00276
Низкий
7 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-20
NVD-CWE-Other
Связанные уязвимости
CVSS3: 7
github
больше 5 лет назад
Potential access control security issue in apollo-adminservice
EPSS
Процентиль: 51%
0.00276
Низкий
7 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-20
NVD-CWE-Other