漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apollo: Apollo Portal release endpoint allows cross-application configuration disclosure via releaseId
Vulnerability Description
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Apollo 授权问题漏洞
Vulnerability Description
Apollo Apollo是Apollo公司的一个可靠的配置管理系统。 Apollo 2.5.0之前版本存在授权问题漏洞,该漏洞源于Apollo Portal在configView.memberOnly.envs启用时,通过GET /envs/{env}/releases/{releaseId}请求发布版本时未验证应用和命名空间权限,可能导致低权限Portal用户在获取或猜测到有效releaseId后,从其他应用和命名空间读取配置数据。
CVSS Information
N/A
Vulnerability Type
N/A