QID 981098
QID 981098: Java (maven) Security Update for com.ctrip.framework.apollo:apollo (GHSA-fvx3-g627-phm2)
An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fvx3-g627-phm2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-fvx3-g627-phm2 -
github.com/advisories/GHSA-fvx3-g627-phm2
CVEs related to QID 981098
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fvx3-g627-phm2 | com.ctrip.framework.apollo:apollo |
|