CVE-2024-43397

Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apolloconfig:apollo:*:*:*:*:*:*:*:*

History

26 Aug 2024, 18:28

Type Values Removed Values Added
CPE cpe:2.3:a:apolloconfig:apollo:*:*:*:*:*:*:*:*
Summary
  • (es) Apollo es un sistema de gestión de configuración. Existe una vulnerabilidad en la función de configuración de sincronización que permite a los usuarios crear solicitudes específicas para eludir las comprobaciones de permisos. Este exploit les permite modificar un espacio de nombres sin los permisos necesarios. El problema se solucionó con una verificación de parámetros de entrada que se lanzó en la versión 2.3.0.
First Time Apolloconfig
Apolloconfig apollo
CWE NVD-CWE-Other
References () https://github.com/apolloconfig/apollo/commit/f55b419145bf9d4f2f51dd4cd45108229e8d97ed - () https://github.com/apolloconfig/apollo/commit/f55b419145bf9d4f2f51dd4cd45108229e8d97ed - Patch
References () https://github.com/apolloconfig/apollo/pull/5192 - () https://github.com/apolloconfig/apollo/pull/5192 - Issue Tracking, Patch
References () https://github.com/apolloconfig/apollo/releases/tag/v2.3.0 - () https://github.com/apolloconfig/apollo/releases/tag/v2.3.0 - Release Notes
References () https://github.com/apolloconfig/apollo/security/advisories/GHSA-c6c3-h4f7-3962 - () https://github.com/apolloconfig/apollo/security/advisories/GHSA-c6c3-h4f7-3962 - Vendor Advisory

20 Aug 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-20 15:15

Updated : 2024-08-26 18:28


NVD link : CVE-2024-43397

Mitre link : CVE-2024-43397

CVE.ORG link : CVE-2024-43397


JSON object : View

Products Affected

apolloconfig

  • apollo
CWE
NVD-CWE-Other CWE-284

Improper Access Control