Description
Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any confirmation from the Portal admin. Cookie SameSite strategy was set to Lax in version 2.1.0. As a workaround, avoid visiting unknown source pages.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0700 | Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any confirmation from the Portal admin. Cookie SameSite strategy was set to Lax in version 2.1.0. As a workaround, avoid visiting unknown source pages. |
Github GHSA |
GHSA-fmxq-v8mg-qh25 | apollo-portal has potential CSRF issue |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:08:07.214Z
Reserved: 2023-02-07T17:10:00.738Z
Link: CVE-2023-25569
No data.
Status : Modified
Published: 2023-02-20T16:15:10.503
Modified: 2024-11-21T07:49:44.917
Link: CVE-2023-25569
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA