Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0609 | Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service. Malicious hackers may access eureka directly to mock apollo-configservice and apollo-adminservice. Login authentication for eureka was added in version 2.1.0. As a workaround, avoid exposing apollo-configservice to the internet. |
Github GHSA |
GHSA-368x-wmmg-hq5c | Apollo has potential access control security issue in eureka |
Mon, 10 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:08:01.441Z
Reserved: 2023-02-07T17:10:00.739Z
Link: CVE-2023-25570
Updated: 2024-08-02T11:25:19.249Z
Status : Modified
Published: 2023-02-20T16:15:10.593
Modified: 2024-11-21T07:49:45.037
Link: CVE-2023-25570
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA