PT-2021-19860 · Unknown · Apollos Apps

Published

2021-06-16

·

Updated

2022-07-02

·

CVE-2021-32691

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apollos Apps versions prior to 2.20.0
Description Apollos Apps is an open source platform for launching church-related apps. In affected versions, new user registrations can access anyone's account by only knowing their basic profile information, such as name, birthday, and gender. This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages, like giving and events.
Recommendations For versions prior to 2.20.0, update to version 2.20.0 to resolve the issue. As a temporary workaround, one can patch their server by overriding the create data source method on the People class. This involves creating a duplicate person and then patching the new person with their profile details, as shown in the provided code snippet.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32691
GHSA-R578-PJ6F-R4FF

Affected Products

Apollos Apps