QID 980043
QID 980043: Java (maven) Security Update for com.ctrip.framework.apollo:apollo-core (GHSA-xpmx-h7xq-xffh)
Security update has been released for com.ctrip.framework.apollo:apollo-core to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
If users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is designed to work in intranet and it doesn't have built-in access control. Malicious hackers may access apollo-adminservice apis directly to access/edit the application's configurations.
Solution
Access control for admin service was added in #3233 and was released in [v1.7.1](https://github.com/ctripcorp/apollo/releases/tag/v1.7.1).Workaround:
To fix the potential issue without upgrading, simply follow the advice that do not expose apollo-adminservice to internet.
To fix the potential issue without upgrading, simply follow the advice that do not expose apollo-adminservice to internet.
Vendor References
- GHSA-xpmx-h7xq-xffh -
github.com/advisories/GHSA-xpmx-h7xq-xffh
CVEs related to QID 980043
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xpmx-h7xq-xffh | com.ctrip.framework.apollo:apollo-core |
|