PT-2020-14243 · Apollo · Apollo-Adminservice
Lexu
·
Published
2020-09-10
·
Updated
2021-11-18
·
CVE-2020-15170
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
apollo-adminservice versions prior to 1.7.1
Description
The issue arises when apollo-adminservice is exposed to the internet, which is not recommended, as it is designed to work in an intranet and lacks built-in access controls. This could allow malicious hackers to access apollo-adminservice APIs directly, potentially accessing or editing the application's configurations.
Recommendations
For versions prior to 1.7.1, to fix the potential issue without upgrading, simply follow the advice to not expose apollo-adminservice to the internet.
For version 1.7.1 and later, no additional actions are required as access control for admin service was added in this version.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apollo-Adminservice