com.ctrip.framework.apollo:apollo
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.ctrip.framework.apollo:apollopage 1 of 1
- CVE-2019-10686CRITICALCVSS 10.0EG 10.02019-04-01
vulnerable: 1.0.0 ... 1.3.0 (6 versions)
An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.
- CVE-2023-25569MEDIUMCVSS 5.7EG 5.7✓ Fixed in 2.1.02023-02-20
vulnerable: 1.0.0 ... 2.0.1 (19 versions)
Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that …
- CVE-2023-25570HIGHCVSS 7.5EG 7.5✓ Fixed in 2.1.02023-02-20
vulnerable: 1.0.0 ... 2.0.1 (19 versions)
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature ena…
- CVE-2024-43397MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.3.02024-08-20
vulnerable: 1.0.0 ... 2.0.1 (19 versions)
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace with…
Check whether com.ctrip.framework.apollo:apollo is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.ctrip.framework.apollo:apollo CVEs against the assets you own.
Start Free Scan →